Security feature bypass in NoScript - #VU14742
Published: September 11, 2018
NoScript
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass implemented security features.
The vulnerability exists due to an error when processing "Content-Type" header. A remote attacker can bypass restrictions imposed by the NoScript browser extension via "text/html;/json" value for the "Content-Type" header and execute arbitrary JavaScript code in browser. The vulnerable extension is used by Tor and Firefox ESR browsers.