VulnerabilityModified
CVE-2019-13075
Tor Browser through 8.5.3 has an information exposure vulnerability.
MEDIUM 5.3EPSS 1.86%
Does this matter?
Lower severity and a low EPSS score (1.86%). Track it; it rarely justifies an emergency change on its own.
Description
Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.86% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- torproject/tor browser
- Source
- cve@mitre.org
References
- https://hackerone.com/reports/588239Exploit, Issue Tracking, Third Party Advisory
- https://trac.torproject.org/projects/tor/ticket/30657Vendor Advisory
- https://hackerone.com/reports/588239Exploit, Issue Tracking, Third Party Advisory
- https://trac.torproject.org/projects/tor/ticket/30657Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.