Total vulnerabilities in the database
When a parent page loaded a child in an iframe with unsafe-inline
, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Software | From | Fixed in |
---|---|---|
mozilla / firefox | - | 122.0 |
mozilla / thunderbird | - | 115.7 |
mozilla / firefox_esr | - | 115.7 |
debian / debian_linux | 10.0 | 10.0.x |