CVE-2019-11737 PUBLISHED

If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.

EPSS 0.13% · 32.8th percentile

Risk Scores

EPSS Score
0.13%
32.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSfirefox55.0.2+build1-0ubuntu0.16.04.1, 41.0.2+build2-0ubuntu1, 42.0+build2-0ubuntu1
Ubuntu:18.04:LTSfirefox62.0+build2-0ubuntu0.18.04.3, 56.0+build6-0ubuntu1, 57.0.1+build2-0ubuntu1
Ubuntu:18.04:LTSmozjs380, 38.8.0~repack1-0ubuntu4, 38.8.0~repack1-0ubuntu3
Ubuntu:20.04:LTSmozjs5252.9.1-1ubuntu3, 0, 52.9.1-1build1
Ubuntu:18.04:LTSmozjs5252.3.1-7fakesync1, 52.3.1-0ubuntu3, 0

Timeline

References

Open in Interactive Console →