Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Firefox | Mozilla | 33.0 (including) | 33.0 (including) |
| Seamonkey | Mozilla | * | 2.30 (including) |
| Firefox | Ubuntu | devel | * |
| Firefox | Ubuntu | lucid | * |
| Firefox | Ubuntu | precise | * |
| Firefox | Ubuntu | trusty | * |
| Firefox | Ubuntu | upstream | * |
| Firefox | Ubuntu | utopic | * |