If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 86.0 |
| mozilla / firefox_esr | - | 78.8 |
| mozilla / thunderbird | - | 78.8 |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |