If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2575-1 | firefox-esr security update |
Debian DLA |
DLA-2578-1 | thunderbird security update |
Debian DSA |
DSA-4862-1 | firefox-esr security update |
Debian DSA |
DSA-4866-1 | thunderbird security update |
EUVD |
EUVD-2021-10889 | If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8. |
Ubuntu USN |
USN-4756-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-4936-1 | Thunderbird vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-03T19:14:09.815Z
Reserved: 2021-01-13T00:00:00
Link: CVE-2021-23968
No data.
Status : Modified
Published: 2021-02-26T02:15:12.820
Modified: 2024-11-21T05:52:07.210
Link: CVE-2021-23968
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN