Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26910
HistorySep 21, 2020 - 6:25 a.m.

Content Security Policy Bypass

2020-09-2106:25:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
csp bypass
firefox
security directive

EPSS

0.001

Percentile

38.7%

firefox is vulnerable to content security policy (CSP) bypass. An attacker is able to bypass CSP directives by using a wildcard '*'which causes any port or path restriction of the directive to be ignored.