CVE-2021-23969 Information
Description
As specified in the W3C Content Security Policy draft when creating a violation report �ser agents need to ensure that the source file is the URL requested by the page pre-redirects. If that’s not possible user agents need to strip the URL down to an origin to avoid unintentional leakage.\ Under certain types of redirects Firefox incorrectly set the source file to be the destination of the redirects. This was fixed to be the redirect destination’s origin. This vulnerability affects Firefox < 86 Thunderbird < 78.8 and Firefox ESR < 78.8.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Reference
https://bugzilla.mozilla.org/show_bug.cgi?id=1542194 https://www.mozilla.org/security/advisories/mfsa2021-08/ https://www.mozilla.org/security/advisories/mfsa2021-09/ https://www.mozilla.org/security/advisories/mfsa2021-07/ https://lists.debian.org/debian-lts-announce/2021/03/msg00000.html https://www.debian.org/security/2021/dsa-4866 https://security.gentoo.org/glsa/202104-09 https://security.gentoo.org/glsa/202104-10
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: