Vulnerability Description
The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy-authorization credentials from the listed request headers, which allows attackers to obtain sensitive information by reading a report, related to incorrect host resolution that occurs with certain redirects.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 4.0 |
| Mozilla | Seamonkey | 1.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.html
- http://www.mozilla.org/security/announce/2011/mfsa2011-29.htmlVendor Advisory
- http://www.mozilla.org/security/announce/2011/mfsa2011-33.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=664983
- https://bugzilla.mozilla.org/show_bug.cgi?id=679588
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.html
- http://www.mozilla.org/security/announce/2011/mfsa2011-29.htmlVendor Advisory
- http://www.mozilla.org/security/announce/2011/mfsa2011-33.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=664983
- https://bugzilla.mozilla.org/show_bug.cgi?id=679588
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
FAQ
What is CVE-2011-2990?
CVE-2011-2990 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy-authorization creden...
How severe is CVE-2011-2990?
CVE-2011-2990 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2990?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey.