CVE-2014-1591: Medium severity firefox vulnerability
Published Dec 11, 2014
·Updated
Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.
Affected Software
2 affected components
Mozilla Firefox=33.0
Mozilla SeaMonkey<=2.30
Event History
Dec 11, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1591?
CVE-2014-1591 has a medium severity rating due to the potential exposure of sensitive information.
2
How do I fix CVE-2014-1591?
To fix CVE-2014-1591, update Mozilla Firefox to version 33.1 or later and SeaMonkey to version 2.31 or later.
3
What are the vulnerable versions associated with CVE-2014-1591?
CVE-2014-1591 affects Mozilla Firefox 33.0 and SeaMonkey versions prior to 2.31.
4
What type of attack does CVE-2014-1591 enable?
CVE-2014-1591 allows remote attackers to obtain sensitive information through CSP violation reports after a redirect.
5
What is the impact of CVE-2014-1591?
The impact of CVE-2014-1591 is the potential unauthorized disclosure of sensitive information from users.