CVE-2017-7808: Infoleak
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.
Other sources
A content security policy (CSP) frame-ancestors directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information.
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7798
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7806
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7804
- CVE-2017-7791
- CVE-2017-7808
- CVE-2017-7782
- CVE-2017-7781
- CVE-2017-7794
- CVE-2017-7803
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7790
- CVE-2017-7796
- CVE-2017-7797
- CVE-2017-7780
- CVE-2017-7779
Frequently Asked Questions
What is the severity of CVE-2017-7808?
CVE-2017-7808 has a moderate severity level due to the potential for cross-origin information leak.
How do I fix CVE-2017-7808?
To fix CVE-2017-7808, update your Mozilla Firefox to version 55 or later.
What versions of Firefox are affected by CVE-2017-7808?
CVE-2017-7808 affects Firefox versions prior to 55.
What type of vulnerability is CVE-2017-7808?
CVE-2017-7808 is a cross-origin information leak vulnerability related to the content security policy.
Can CVE-2017-7808 lead to security risks?
Yes, CVE-2017-7808 can lead to security risks by leaking sensitive path information across origins.