CVE-2019-17002

Publication date

2020-01-08 21:13:48

Family

mozilla

State

PUBLISHED

Description

If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.