Description
A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16106 | A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration. |
References
History
No history.
Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-09-03T18:29:33.745Z
Reserved: 2024-01-08T06:20:53.953Z
Link: CVE-2024-0310
Updated: 2024-08-01T18:04:49.037Z
Status : Modified
Published: 2024-01-10T11:15:10.580
Modified: 2024-11-21T08:46:17.807
Link: CVE-2024-0310
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD