Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Matthew Somerville

#39112de 53,639
7.1CVSS total
Vulnerabilidades · 1
PT-2019-4867
7.1
2019-12-03
Mozilla · Firefox · CVE-2019-17020
**Name of the Vulnerable Software and Affected Versions** Firefox versions prior to 72 **Description** The issue is related to a security policy error that does not apply to the contents of an XSL stylesheet when an XML file is served with a Content Security Policy and includes an XSL stylesheet. This could allow a remote attacker to compromise data integrity, particularly if the XSL sheet includes JavaScript, thereby bypassing the restrictions of the Content Security Policy applied to the XML document. **Recommendations** For Firefox versions prior to 72, update to version 72 or later to resolve the issue. As a temporary workaround, consider restricting the use of XSL stylesheets in XML files served with a Content Security Policy until a patch is applied.