If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-04T23:03:32.672Z
Reserved: 2019-05-03T00:00:00
Link: CVE-2019-11737

No data.

Status : Modified
Published: 2019-09-27T18:15:11.520
Modified: 2024-11-21T04:21:41.350
Link: CVE-2019-11737


No data.