PT-2019-4546 · Mozilla+2 · Firefox+2

Vinothkumar Nagasayanan

+1

·

Publicado

2019-03-19

·

Atualizado

2024-12-12

·

CVE-2019-9803

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 66
Description The issue is related to the Upgrade-Insecure-Requests (UIR) specification and Content Security Policy (CSP) in Firefox. When UIR is enabled through CSP, Firefox should upgrade navigation to a same-origin URL to HTTPS. However, in some cases, Firefox incorrectly navigates to an HTTP URL instead of performing the security upgrade, potentially allowing man-in-the-middle attacks on linked resources. This could allow a remote attacker to access and compromise confidential data.
Recommendations For versions prior to 66, update to version 66 or later to resolve the issue. As a temporary workaround, consider disabling the UIR feature through CSP until a patch is available. Restrict access to sensitive data and resources to minimize the risk of exploitation.

Correção

Origin Validation Error

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1561
ALT-PU-2019-2324
ALT-PU-2019-2486
BDU:2020-00592
CVE-2019-9803
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3918-1
USN-3918-2
USN-3918-3
USN-3918-4

Produtos afetados

Alt Linux
Firefox
Ubuntu