First published: Tue Oct 22 2019(Updated: )
A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-2019-17000.*Note: This flaw only affected Firefox 69 and was not present in earlier versions.*. This vulnerability affects Firefox < 70.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <70 | 70 |
Mozilla Firefox | =69.0 | |
debian/firefox | 133.0.3-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-17001 is a vulnerability that allows bypassing a Content-Security-Policy in Firefox 69 and executing JavaScript in a protected document.
CVE-2019-17001 works by using an object tag to bypass a Content-Security-Policy that blocks in-line scripts and execute JavaScript in a protected document.
CVE-2019-17001 only affects Firefox 69 and is not present in earlier versions.
CVE-2019-17001 has a severity value of 4 which is classified as medium.
To fix CVE-2019-17001, it is recommended to update Firefox to version 70 or later, as this vulnerability was remedied in Firefox 70.