Security Advisory

CVE-2011-2990

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-08-18 18:00:00
Last updated 2024-08-06 23:22:26
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy-authorization credentials from the listed request headers, which allows attackers to obtain sensitive information by reading a report, related to incorrect host resolution that occurs with certain redirects.