CVE-2019-9803

Name
CVE-2019-9803
Description
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle attacks on the linked resources. This vulnerability affects Firefox < 66.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2019-07/
Third Party Advisory https://w3c.github.io/webappsec-upgrade-insecure-requests/
Issue Tracking https://bugzilla.mozilla.org/show_bug.cgi?id=1515863
Issue Tracking https://bugzilla.mozilla.org/show_bug.cgi?id=1437009

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* firefox >= None < 66.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status