Related Vulnerabilities: CVE-2020-6813  

A Content Security Policy bypass has been found in Firefox before 74. When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy.

Severity Low

Remote Yes

Type Access restriction bypass

Description

A Content Security Policy bypass has been found in Firefox before 74. When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy.

AVG-1112 firefox 73.0.1-1 74.0-1 Critical Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2020-08/#CVE-2020-6813
https://bugzilla.mozilla.org/show_bug.cgi?id=1605814