Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-11738
HistorySep 27, 2019 - 6:15 p.m.

Input validation

2019-09-2718:15:00
PRIOn knowledge base
www.prio-n.com
7

6.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.8%

If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP permissions. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

CPENameOperatorVersion
firefoxlt69.0
firefox_esrlt68.1.0
leapeq15.0
leapeq15.1