CVE-2019-11738: Medium severity firefox vulnerability
If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP permissions.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-11738.
What is the severity of CVE-2019-11738?
CVE-2019-11738 has a low severity.
Which software is affected by CVE-2019-11738?
Mozilla Firefox ESR versions up to 68.1 and Mozilla Firefox versions up to 69 are affected by CVE-2019-11738.
How can a malicious JavaScript content be executed with CVE-2019-11738?
A Content Security Policy (CSP) directive that uses a hash-based source taking the empty string as input allows execution of any javascript: URIs.
Is there a fix available for CVE-2019-11738?
Yes, upgrading Mozilla Firefox ESR to version 68.1 or upgrading Mozilla Firefox to version 69 will fix CVE-2019-11738.