Vulnerability Name: | CVE-2019-17020 (CCN-174059) | ||||||||||||||||||||||||
Assigned: | 2019-09-30 | ||||||||||||||||||||||||
Published: | 2020-01-07 | ||||||||||||||||||||||||
Updated: | 2021-07-21 | ||||||||||||||||||||||||
Summary: | If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the Content Security Policy applied to the XML document. This vulnerability affects Firefox < 72. | ||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-17020 Source: MISC Type: Permissions Required https://bugzilla.mozilla.org/show_bug.cgi?id=1597645 Source: XF Type: UNKNOWN firefox-cve201917020-sec-bypass(174059) Source: UBUNTU Type: Third Party Advisory USN-4234-1 Source: CCN Type: Mozilla Foundation Security Advisory 2020-01 Security Vulnerabilities fixed in Firefox 72 Source: CONFIRM Type: Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2020-01/ | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |