PT-2020-19241 · Mozilla+2 · Firefox+2

Matheus Vrech

·

Published

2020-03-10

·

Updated

2024-12-12

·

CVE-2020-6813

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 74
Description The issue allows an attacker to inject arbitrary styles into a CSS block by exploiting the @import statement, bypassing the intent of the Content Security Policy when protecting CSS blocks with the nonce feature.
Recommendations For versions prior to 74, update to version 74 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2020-1486
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2020-3442
ALT-PU-2021-1368
ALT-PU-2021-3368
CVE-2020-6813
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2020:1899-1
USN-4299-1

Affected Products

Alt Linux
Firefox
Ubuntu