First published: Tue Sep 03 2019(Updated: )
If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <69 | 69 |
Mozilla Firefox | <69.0 | |
debian/firefox | 132.0.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-11737 is a vulnerability that affects Mozilla Firefox versions up to and including version 69.
CVE-2019-11737 has a low severity rating.
If a wildcard (*) is specified for the host in CSP directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content.
Mozilla Firefox versions up to and including version 69 are affected by CVE-2019-11737.
Update your Mozilla Firefox browser to version 69 or higher to fix the CVE-2019-11737 vulnerability.