CVE Database
/

CVE-2019-17022

Back to search

CVE-2019-17022

Published: Jan 8, 2020

Modified: Aug 5, 2024

PUBLISHED

Description

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

VendorProductVersions

Mozilla

Firefox ESR

affected
before 68.4

Mozilla

Firefox

affected
before 72

References

DSA-4600
vendor-advisory
x_refsource_DEBIAN
USN-4234-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2020:0085
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0086
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0111
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0060
vendor-advisory
x_refsource_SUSE
RHSA-2020:0120
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0123
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0127
vendor-advisory
x_refsource_REDHAT
USN-4241-1
vendor-advisory
x_refsource_UBUNTU
DSA-4603
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2020:0094
vendor-advisory
x_refsource_SUSE
RHSA-2020:0292
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0295
vendor-advisory
x_refsource_REDHAT
GLSA-202003-02
vendor-advisory
x_refsource_GENTOO
USN-4335-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now