Beveiligingsadvies

CVE-2024-0747

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-01-23 13:48:16
Laatst bijgewerkt 2025-05-22 17:40:22
Toegewezen door mozilla
CVSS-score 6.5
Status PUBLISHED

Beschrijving

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.