CVE-2019-17001Cross-site Scripting in Firefox

7 documents7 sources
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 55.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8
Latest updateMay 24

Description

A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-2019-17000.*Note: This flaw only affected Firefox 69 and was not present in earlier versions.*. This vulnerability affects Firefox < 70.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

debiandebian/firefox< firefox 70.0-1 (sid)
Ubuntumozilla/firefox< 70.0+build2-0ubuntu0.16.04.1+2
NVDmozilla/firefox69.0

🔴Vulnerability Details

2
GHSA
GHSA-pcxf-xvjr-2qpp: A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-sit2022-05-24
OSV
CVE-2019-17001: A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-sit2019-10-23

💥Exploits & PoCs

2
Exploit-DB
SmarterMail Build 6985 - Remote Code Execution2020-12-09
Metasploit
SmarterTools SmarterMail less than build 6985 - .NET Deserialization Remote Code Execution

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2019-10-23
Debian
CVE-2019-17001: firefox - A Content-Security-Policy that blocks in-line scripts could be bypassed using an...2019