If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2019-09-27T17:20:17
Updated: 2024-08-04T23:03:32.672Z
Reserved: 2019-05-03T00:00:00
Link: CVE-2019-11737
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-09-27T18:15:11.520
Modified: 2024-11-21T04:21:41.350
Link: CVE-2019-11737
Redhat