CVE-2019-11738

If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP permissions. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

Information

Published : 2019-09-27 18:15

Updated : 2021-07-21 11:39


NVD link : CVE-2019-11738

Mitre link : CVE-2019-11738


JSON object : View

Products Affected

mozilla

  • firefox_esr
  • firefox
CWE
CWE-276

Incorrect Default Permissions