Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements additional measures to prevent web applications from directly embedding the settings page, but this mechanism can be bypassed.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-18528 Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements additional measures to prevent web applications from directly embedding the settings page, but this mechanism can be bypassed.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T21:38:46.507Z

Reserved: 2019-02-25T00:00:00

Link: CVE-2019-9147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-09T21:15:11.193

Modified: 2024-11-21T04:51:04.787

Link: CVE-2019-9147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.