If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-3407 | If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69. |
Ubuntu USN |
USN-4122-1 | Firefox vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-04T23:03:32.672Z
Reserved: 2019-05-03T00:00:00
Link: CVE-2019-11737
No data.
Status : Modified
Published: 2019-09-27T18:15:11.520
Modified: 2024-11-21T04:21:41.350
Link: CVE-2019-11737
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN