First published: Tue Aug 08 2017(Updated: )
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <55 | 55 |
Firefox | <55.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7808 has a moderate severity level due to the potential for cross-origin information leak.
To fix CVE-2017-7808, update your Mozilla Firefox to version 55 or later.
CVE-2017-7808 affects Firefox versions prior to 55.
CVE-2017-7808 is a cross-origin information leak vulnerability related to the content security policy.
Yes, CVE-2017-7808 can lead to security risks by leaking sensitive path information across origins.