CVE-2020-6813
25.03.2020, 22:15
When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 74.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||||||||||||||
mozjs38 |
| ||||||||||||||||||||||||||
mozjs52 |
| ||||||||||||||||||||||||||
mozjs60 |
|