CVE-2019-17002
08.01.2020, 22:15
If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 70.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||||||||||||||||
mozjs38 |
| ||||||||||||||||||||||||||||
mozjs52 |
| ||||||||||||||||||||||||||||
mozjs60 |
|