If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the Content Security Policy applied to the XML document. This vulnerability affects Firefox < 72.
                
            References
                    | Link | Resource | 
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1597645 | Permissions Required | 
| https://usn.ubuntu.com/4234-1/ | Third Party Advisory | 
| https://www.mozilla.org/security/advisories/mfsa2020-01/ | Vendor Advisory | 
| https://bugzilla.mozilla.org/show_bug.cgi?id=1597645 | Permissions Required | 
| https://usn.ubuntu.com/4234-1/ | Third Party Advisory | 
| https://www.mozilla.org/security/advisories/mfsa2020-01/ | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
History
                    21 Nov 2024, 04:31
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1597645 - Permissions Required | |
| References | () https://usn.ubuntu.com/4234-1/ - Third Party Advisory | |
| References | () https://www.mozilla.org/security/advisories/mfsa2020-01/ - Vendor Advisory | 
Information
                Published : 2020-01-08 22:15
Updated : 2024-11-21 04:31
NVD link : CVE-2019-17020
Mitre link : CVE-2019-17020
CVE.ORG link : CVE-2019-17020
JSON object : View
Products Affected
                canonical
- ubuntu_linux
mozilla
- firefox
CWE
                
                    
                        
                        CWE-611
                        
            Improper Restriction of XML External Entity Reference
