Description
Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-1667 | Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect. |
Ubuntu USN |
USN-2424-1 | Firefox vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-06T09:42:36.657Z
Reserved: 2014-01-16T00:00:00.000Z
Link: CVE-2014-1591
No data.
Status : Modified
Published: 2014-12-11T11:59:05.257
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-1591
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN