Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | 33.0 (including) | 33.0 (including) |
Seamonkey | Mozilla | * | 2.30 (including) |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | lucid | * |
Firefox | Ubuntu | precise | * |
Firefox | Ubuntu | trusty | * |
Firefox | Ubuntu | upstream | * |
Firefox | Ubuntu | utopic | * |