CVE-2017-7834Cross-site Scripting in Mozilla Firefox

CWE-79Cross-site Scripting12 documents5 sources
Severity
6.1MEDIUMNVD
OSV9.8
EPSS
1.0%
top 23.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy including the execution of JavaScript. In prior versions when "data:" documents also inherited the context of the original page this would allow for potential cross-site scripting (XSS) attacks. This vulnerability affects Firefox < 57.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

debiandebian/firefox< firefox 57.0-1 (sid)
CVEListV5mozilla/firefoxunspecified57
Ubuntumozilla/firefox< 57.0+build4-0ubuntu0.14.04.4+8
NVDmozilla/firefox56.0.2

🔴Vulnerability Details

6
GHSA
GHSA-5q3m-44wf-w4hc: A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy includin2022-05-14
OSV
firefox regression2018-01-03
OSV
firefox regressions2017-12-01
OSV
firefox regression2017-11-27
OSV
firefox vulnerabilities2017-11-16

📋Vendor Advisories

5
Ubuntu
Firefox regression2018-01-03
Ubuntu
Firefox regressions2017-12-01
Ubuntu
Firefox regression2017-11-27
Ubuntu
Firefox vulnerabilities2017-11-16
Debian
CVE-2017-7834: firefox - A "data:" URL loaded in a new tab did not inherit the Content Security Policy (C...2017