Beveiligingsadvies

CVE-2011-2990

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2011-08-18 18:00:00
Laatst bijgewerkt 2024-08-06 23:22:26
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy-authorization credentials from the listed request headers, which allows attackers to obtain sensitive information by reading a report, related to incorrect host resolution that occurs with certain redirects.