Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ghv2-cp6r-w334

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.

When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.

EPSS

Процентиль: 66%
0.01204
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.

CVSS3: 5.3
redhat
больше 6 лет назад

When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.

CVSS3: 5.3
nvd
больше 6 лет назад

When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.

CVSS3: 5.3
debian
больше 6 лет назад

When protecting CSS blocks with the nonce feature of Content Security ...

suse-cvrf
около 6 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 66%
0.01204
Низкий