Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2019-07-23T13:18:19

Updated: 2019-10-06T14:06:15

Reserved: 2019-05-03T00:00:00


Link: CVE-2019-11716

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-07-23T14:15:15.873

Modified: 2019-08-15T18:15:18.007


Link: CVE-2019-11716

JSON object: View

cve-icon Redhat Information

No data.

CWE