CVE Vulnerabilities

CVE-2011-2990

Published: Aug 18, 2011 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy-authorization credentials from the listed request headers, which allows attackers to obtain sensitive information by reading a report, related to incorrect host resolution that occurs with certain redirects.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0 4.0
Firefox Mozilla 4.0.1 4.0.1
Firefox Mozilla 5.0 5.0
Firefox Ubuntu hardy *
Firefox Ubuntu natty *
Firefox Ubuntu upstream *
Firefox-3.0 Ubuntu hardy *
Seamonkey Ubuntu hardy *
Thunderbird Ubuntu hardy *
Xulrunner-1.9.2 Ubuntu hardy *
Xulrunner-2.0 Ubuntu natty *
Xulrunner-2.0 Ubuntu upstream *

References