If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mozilla
Published: 2019-09-27T17:20:17
Updated: 2024-08-04T23:03:32.672Z
Reserved: 2019-05-03T00:00:00
Link: CVE-2019-11737

No data.

Status : Modified
Published: 2019-09-27T18:15:11.520
Modified: 2024-11-21T04:21:41.350
Link: CVE-2019-11737
