Описание
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-12398
- https://bugzilla.mozilla.org/show_bug.cgi?id=1460538
- https://bugzilla.mozilla.org/show_bug.cgi?id=1488061
- https://usn.ubuntu.com/3801-1
- https://www.mozilla.org/security/advisories/mfsa2018-26
- http://www.securityfocus.com/bid/105721
- http://www.securitytracker.com/id/1041944
Связанные уязвимости
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
By using the reflected URL in some special resource URIs, such as chro ...
Уязвимость браузера Firefox, связанная с отсутствием мер по очистке входных данных, позволяющая нарушителю обойти защитный механизм CSP