PT-2019-5020 · Mozilla+2 · Firefox+2

Matheus Vrech

·

Published

2019-09-28

·

Updated

2024-12-12

·

CVE-2019-17001

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions 69
Description The issue is related to a Content-Security-Policy bypass that allows the execution of JavaScript in a protected document through an object tag, leading to cross-site scripting. This flaw can be exploited by a remote attacker to gain unauthorized access to confidential data and impact data integrity.
Recommendations For Firefox version 69, update to version 70 or later to resolve the issue. As a temporary workaround, consider disabling the use of object tags in Firefox until a patch is available. Restrict access to sensitive data and ensure proper input validation to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2800
ALT-PU-2019-3087
ALT-PU-2020-1617
BDU:2020-01652
CVE-2019-17001
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-4165-1
USN-4165-2

Affected Products

Alt Linux
Firefox
Ubuntu