Java Web Start Files Not Prompted as Executable Downloads in Firefox < 67

Java Web Start Files Not Prompted as Executable Downloads in Firefox < 67

CVE-2019-11696 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.

Learn more about our Web App Pen Testing.