Mozilla Firefox CVE-2016-1955 Information Disclosure Vulnerability

description-logoDescription

Security researcher Muneaki Nishimura (nishimunea) of Recruit Technologies Co.,Ltd. reported that Content Security Policy (CSP) violation reports contained full path information for cross-origin iframe navigations in violation of the CSP specification. This could result in information disclosure.

affected-products-logoAffected Applications

Firefox

CVE References

CVE-2016-1955