Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.
| Software | From | Fixed in |
|---|---|---|
| oracle / solaris | 11.3 | 11.3.x |
| mozilla / firefox | - | 39.0.3.x |
| opensuse / opensuse | 13.1 | 13.1.x |
| opensuse / opensuse | 13.2 | 13.2.x |