CVE-2019-9808: Medium severity firefox vulnerability
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-9808?
The severity of CVE-2019-9808 is medium with a severity value of 5.3.
How does CVE-2019-9808 affect Mozilla Firefox?
CVE-2019-9808 affects Mozilla Firefox versions up to and including 66.0, and it may cause confusion for users when displaying the originating domain for WebRTC permission notifications.
Which websites provide more information about CVE-2019-9808?
You can find more information about CVE-2019-9808 on Bugzilla and the Mozilla security advisories page.
What is the Common Weakness Enumeration (CWE) for CVE-2019-9808?
The CWE for CVE-2019-9808 is CWE-346.
How can I fix the vulnerability CVE-2019-9808?
To fix CVE-2019-9808, update Mozilla Firefox to version 66.0.1 or higher.