CVE-2019-9803

CVSS v3.0 7.4 (High)
74% Progress
CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 0.15 % (53th)
0.15% Progress
Affected Products 1
Advisories 5

The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle attacks on the linked resources. This vulnerability affects Firefox < 66.

Weaknesses
CWE-346
Origin Validation Error
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2019-04-26 17:29:03
(5 years ago)
Updated Date
2019-04-30 23:51:48
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 66.0 version cpe:2.3:a:mozilla:firefox < 66.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...