CVE-2019-17020 Information
Share on:
Feb 14, 2021
cve
Description
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript it would bypass any of the restrictions of the Content Security Policy applied to the XML document. This vulnerability affects Firefox 72.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Reference
https://bugzilla.mozilla.org/show_bug.cgi?id=1597645 https://usn.ubuntu.com/4234-1/ https://www.mozilla.org/security/advisories/mfsa2020-01/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
6.5