5
CVSSv2

CVE-2011-2990

Published: 18/08/2011 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x prior to 2.3, and possibly other products does not remove proxy-authorization credentials from the listed request headers, which allows malicious users to obtain sensitive information by reading a report, related to incorrect host resolution that occurs with certain redirects.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 4.0

mozilla firefox 4.0.1

mozilla firefox 5.0

mozilla seamonkey 1.1.8

mozilla seamonkey 2.0.8

mozilla seamonkey 2.1

mozilla seamonkey 2.0.9

mozilla seamonkey 2.0.1

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.19

mozilla seamonkey 1.1.18

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.15

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0.10

mozilla seamonkey 1.0

mozilla seamonkey 1.0.9

mozilla seamonkey 2.0.3

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1

mozilla seamonkey 2.0

mozilla seamonkey 1.0.2

mozilla seamonkey 2.0.7

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.5

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.7

mozilla seamonkey 1.1.13

mozilla seamonkey 1.0.5

mozilla seamonkey 2.0.11

mozilla seamonkey 1.1.7

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.5

mozilla seamonkey 1.1.9

mozilla seamonkey 1.5.0.8

mozilla seamonkey 1.5.0.9

mozilla seamonkey 1.0.6

mozilla seamonkey 2.0.4

mozilla seamonkey 1.5.0.10

mozilla seamonkey 1.0.3

Vendor Advisories

This update provides a compatible Mozvoikko for Firefox 6 ...
A regression caused Firefox to crash while spell checking in Finnish ...
Multiple Firefox vulnerabilities have been fixed ...
Mozilla Foundation Security Advisory 2011-33 Security issues addressed in SeaMonkey 23 Announced August 16, 2011 Impact Critical Products SeaMonkey Fixed in SeaMonkey 23 ...
Mozilla Foundation Security Advisory 2011-29 Security issues addressed in Firefox 6 Announced August 16, 2011 Impact Critical Products Firefox Fixed in Firefox 6 ...