CVE-2019-13075

Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.
References
Link Resource
https://trac.torproject.org/projects/tor/ticket/30657 Vendor Advisory
https://hackerone.com/reports/588239 Exploit Issue Tracking Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:torproject:tor_browser:*:*:*:*:*:*:*:*

Information

Published : 2019-06-30 07:15

Updated : 2019-07-08 09:03


NVD link : CVE-2019-13075

Mitre link : CVE-2019-13075


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

torproject

  • tor_browser