ZeroHour

CVE-2019-11737

CVSS 3.1
5.3 medium
EPSS
<1%p44
Published
()
Modified
Description

If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.

Vendors
mozilla
Products
firefox
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.