#VU12564 Security restrictions bypass in Mozilla Firefox - CVE-2018-5175
Published: May 10, 2018
Mozilla Firefox
Mozilla
Description
The vulnerability exists due to improper security mechanism of Content Security Policy (CSP) protections on sites that have a script-src policy of 'strict-dynamic'. A remote attacker can inject a reference to a copy of the require.js library that is part of Firefox’s Developer Tools and bypass Content Security Policy (CSP) protections for sites that have a script-src policy of 'strict-dynamic'.