CVE-2021-23968
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report.
as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
MEDIUM · CVSS 4.3
EPSS 0.00425
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules1
YARA rules0