Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30225
HistoryApr 29, 2021 - 11:56 a.m.

Content-Security Policy (CSP) Bypas

2021-04-2911:56:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.001 Low

EPSS

Percentile

43.8%

firefox is vulnerable to content-security policy bypass. Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allows the execution of scripts that should have been blocked.