When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
2024-01-23T14:15:38.463
2025-05-22T18:15:34.830
Modified
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 122.0 | Yes |
| Application | mozilla | firefox_esr | < 115.7 | Yes |
| Application | mozilla | thunderbird | < 115.7 | Yes |
| Operating System | debian | debian_linux | 10.0 | Yes |