CVE-2017-7808
11.06.2018, 21:29
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 55.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||
mozjs38 |
|
Common Weakness Enumeration
References