Back

CRITICAL

Mozilla: Sandboxed about:srcdoc frames do not inherit CSP directives (MFSA 2017-18)

Published Jun 11, 2018

Description

When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jun 11, 2018
Updated Aug 5, 2024
Reserved Apr 12, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 8, 2017