First published: Sun Mar 13 2016(Updated: )
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Suse Package Hub For Suse Linux Enterprise | =12 | |
openSUSE Leap | =42.1 | |
openSUSE openSUSE | =13.1 | |
openSUSE openSUSE | =13.2 | |
Mozilla Firefox | <=44.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.