CVE-2020-6813 — Improper Access Control in Mozilla Firefox
Severity
5.3MEDIUMNVD
OSV6.5
EPSS
0.2%
top 61.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 25
Latest updateMay 24
Description
When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
3GHSA▶
GHSA-ghv2-cp6r-w334: When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject↗2022-05-24
OSV▶
CVE-2020-6813: When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject↗2020-03-11
📋Vendor Advisories
4💬Community
1Bugzilla▶
CVE-2020-6813 Mozilla: @import statements in CSS could bypass the Content Security Policy nonce feature↗2020-04-29