CVE-2019-9803: High severity firefox vulnerability
Last updated 24 July 2024
Other sources
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle attacks on the linked resources.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-9803?
CVE-2019-9803 is a vulnerability in the Upgrade-Insecure-Requests (UIR) specification that affects Mozilla Firefox.
What is the severity level of CVE-2019-9803?
The severity level of CVE-2019-9803 is high, with a CVSS score of 7.4.
How does CVE-2019-9803 affect Firefox?
CVE-2019-9803 affects Firefox by causing navigation to an HTTP URL instead of performing the requested security upgrade when the Upgrade-Insecure-Requests (UIR) is enabled through Content Security Policy (CSP).
How can I fix CVE-2019-9803 in Firefox?
To fix CVE-2019-9803 in Firefox, update to version 66.0 or later.
Where can I find more information about CVE-2019-9803?
You can find more information about CVE-2019-9803 on the Mozilla Bugzilla website and the W3C Upgrade-Insecure-Requests specification.