Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | 33.0 | 33.0 |
Seamonkey | Mozilla | * | 2.30 |