Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.
Mozilla Foundation reports:
CVE-2019-11733: Stored passwords in 'Saved Logins' can
be copied without master password entry
When a master password is set, it is required to be
entered again before stored passwords can be accessed in the 'Saved
Logins' dialog. It was found that locally stored passwords can be
copied to the clipboard thorough the 'copy password' context menu item
without re-entering the master password if the master password had
been previously entered in the same session, allowing for potential
theft of stored passwords.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center