CVE-2014-1591

Currently unrated

Key Information:

Vendor
Mozilla
Vendor
CVE Published:
11 December 2014

Summary

Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.