LiveActive security incident?Get immediate response
CVE Record

CVE-2019-11711: When an inner window is reused, it does not consider the use of document.domain for cross-origin protections.

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a Mozilla browser and mail-client security flaw where normal subdomain boundaries could be bypassed in some document.domain scenarios. A compromised or hostile subdomain could potentially run script against pages on another related subdomain. The main business risk is from unpatched legacy Firefox, Firefox ESR, or Thunderbird installations.

Executive priority

Treat this as a legacy-client cleanup priority. It is not reported as actively exploited in the provided sources, but it can undermine browser trust boundaries for organizations with old Mozilla clients and related subdomain applications.

Technical view

CVE-2019-11711 concerns inner window reuse failing to account for document.domain-based origin relaxation. Where pages on different subdomains used document.domain cooperatively, one page could inject script into arbitrary pages on the other subdomain. Mozilla lists Firefox ESR before 60.8, Firefox before 68, and Thunderbird before 60.8 as affected.

Likely exposure

Exposure is most likely on legacy managed endpoints, long-lived ESR deployments, older Linux desktop packages, or environments still running Thunderbird before 60.8. Risk increases for organizations with related subdomains that historically used document.domain.

Exploitation context

The source bundle does not show CISA KEV listing or active exploitation. Exploitation depends on a specific cross-subdomain document.domain condition and an affected Mozilla client, so this is not a universal server-side exposure.

Researcher notes

Focus validation on client version exposure and document.domain-dependent subdomain trust assumptions. The public description is concise and does not include CVSS, CWE, exploit details, or operational indicators in the provided bundle.

Mitigation direction

  • Update Firefox to version 68 or later.
  • Update Firefox ESR to version 60.8 or later.
  • Update Thunderbird to version 60.8 or later.
  • Apply relevant Debian, openSUSE, Gentoo, or vendor security packages.
  • Review legacy document.domain use across related subdomains.

Validation and detection

  • Inventory managed endpoints for affected Firefox, Firefox ESR, and Thunderbird versions.
  • Confirm no Firefox ESR below 60.8 remains in supported images.
  • Confirm no Firefox below 68 remains in managed browser fleets.
  • Confirm no Thunderbird below 60.8 remains on user systems.
  • Identify applications relying on document.domain across subdomains.
Prepared
Confidence
high
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-11711 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
9Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
MozillaFirefox ESRunspecifiedListed
MozillaFirefoxunspecifiedListed
MozillaThunderbirdunspecifiedListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.