CVE-2019-17001: XSS
A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-2019-17000.Note: This flaw only affected Firefox 69 and was not present in earlier versions.. This vulnerability affects Firefox < 70.
Other sources
A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-2019-17000.Note: This flaw only affected Firefox 69 and was not present in earlier versions.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-17001?
CVE-2019-17001 is a vulnerability that allows bypassing a Content-Security-Policy in Firefox 69 and executing JavaScript in a protected document.
How does CVE-2019-17001 work?
CVE-2019-17001 works by using an object tag to bypass a Content-Security-Policy that blocks in-line scripts and execute JavaScript in a protected document.
Which versions of Firefox are affected by CVE-2019-17001?
CVE-2019-17001 only affects Firefox 69 and is not present in earlier versions.
What is the severity of CVE-2019-17001?
CVE-2019-17001 has a severity value of 4 which is classified as medium.
How can CVE-2019-17001 be fixed?
To fix CVE-2019-17001, it is recommended to update Firefox to version 70 or later, as this vulnerability was remedied in Firefox 70.