Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17002

Опубликовано: 08 янв. 2020
Источник: debian
EPSS Низкий

Описание

If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed70.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-34/#CVE-2019-17002

EPSS

Процентиль: 51%
0.00284
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 6 лет назад

If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.

CVSS3: 4.3
nvd
около 6 лет назад

If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.

github
больше 3 лет назад

If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.

CVSS3: 4.3
fstec
больше 6 лет назад

Уязвимость политики безопасности веб-браузера Firefox, связанная с недостатком механизма проверки вводимых данных, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 51%
0.00284
Низкий