If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 70.0 |