CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. It affects Firefox.
CVE
CVE-2019-17000
Severity
MEDIUM
CVSS
6.1
EPSS
0.81%
Firefox
Original NVD Description
An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if the document's policy explicitly allowed data: URIs. This vulnerability affects Firefox < 70.
Related CVEs
Other vulnerabilities affecting the same vendor(s)