CVE-2019-11737
Last modified
CVE-2019-11737 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 69.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1388015Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-25/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1388015Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-25/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11737?
How severe is CVE-2019-11737?
How do I fix CVE-2019-11737?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1173An elevation of privilege vulnerability exists in the way th…7
- CVE-2019-11730A vulnerability exists where if a user opens a locally saved…6.5
- CVE-2019-11733When a master password is set, it is required to be entered …9.8
- CVE-2019-11734Mozilla developers and community members reported memory saf…9.8
- CVE-2019-11735Mozilla developers and community members reported memory saf…8.8
- CVE-2019-11736The Mozilla Maintenance Service does not guard against files…7
- CVE-2019-11738If a Content Security Policy (CSP) directive is defined that…6.3
- CVE-2019-11739Encrypted S/MIME parts in a crafted multipart/alternative me…6.5
- CVE-2019-1174An elevation of privilege vulnerability exists in the way th…7
- CVE-2019-11740Mozilla developers and community members reported memory saf…8.8
- CVE-2019-11741A compromised sandboxed content process can perform a Univer…6.1
- CVE-2019-11742A same-origin policy violation occurs allowing the theft of …6.5
Are you affected by CVE-2019-11737?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
