Lucene search

K
cvelistMozillaCVELIST:CVE-2019-11738
HistorySep 27, 2019 - 5:19 p.m.

CVE-2019-11738

2019-09-2717:19:57
mozilla
www.cve.org
2

6.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.7%

If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP permissions. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

CNA Affected

[
  {
    "product": "Firefox",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "69",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Firefox ESR",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "68.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]