When a parent page loaded a child in an iframe with ...
Moderate severity
Unreviewed
Published
Jan 23, 2024
to the GitHub Advisory Database
•
Updated May 22, 2025
Description
Published by the National Vulnerability Database
Jan 23, 2024
Published to the GitHub Advisory Database
Jan 23, 2024
Last updated
May 22, 2025
When a parent page loaded a child in an iframe with
unsafe-inline
, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.References