CVE-2019-11716
23.07.2019, 14:15
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 68.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||||||||||||||||||
mozjs38 |
| ||||||||||||||||||||||||||||||
mozjs52 |
| ||||||||||||||||||||||||||||||
mozjs60 |
|
Common Weakness Enumeration
References