CVE-2019-17002 on Ubuntu 18.04 LTS (bionic) - low.
Description:
If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.