Security Advisory

CVE-2017-7834

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-06-11 21:00:00
Last updated 2024-08-05 16:19:28
Assigner mozilla
State PUBLISHED

Description

A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy including the execution of JavaScript. In prior versions when "data:" documents also inherited the context of the original page this would allow for potential cross-site scripting (XSS) attacks. This vulnerability affects Firefox < 57.