CVE-2024-7524
CVE-2024-7524
Título es
CVE-2024-7524
Mar, 06/08/2024 – 13:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-7524
Descripción en
Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox
06/08/2024
06/08/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off