Related Vulnerabilities: CVE-2019-17020  

A Content Security Policy bypass has been found in Firefox 72.0, where the CSP is not applied to XSL stylesheets applied to XML documents. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the Content Security Policy applied to the XML document.

Severity Medium

Remote Yes

Type Access restriction bypass

Description

A Content Security Policy bypass has been found in Firefox 72.0, where the CSP is not applied to XSL stylesheets applied to XML documents. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the Content Security Policy applied to the XML document.

AVG-1084 firefox 71.0-1 72.0-1 Critical Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2020-01/#CVE-2019-17020
https://bugzilla.mozilla.org/show_bug.cgi?id=1597645