First published: Tue Mar 19 2019(Updated: )
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission.
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <66 | 66 |
Mozilla Firefox | <66.0 | |
debian/firefox | 133.0.3-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2019-9808 is medium with a severity value of 5.3.
CVE-2019-9808 affects Mozilla Firefox versions up to and including 66.0, and it may cause confusion for users when displaying the originating domain for WebRTC permission notifications.
You can find more information about CVE-2019-9808 on Bugzilla and the Mozilla security advisories page.
The CWE for CVE-2019-9808 is CWE-346.
To fix CVE-2019-9808, update Mozilla Firefox to version 66.0.1 or higher.