Related Vulnerabilities: CVE-2020-12391  

Documents formed using data: URLs in an object element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin.

Severity Medium

Remote Yes

Type Arbitrary code execution

Description

Documents formed using data: URLs in an object element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin.

AVG-1148 firefox 75.0-1 76.0-1 Critical Testing

https://bugzilla.mozilla.org/show_bug.cgi?id=1457100