CVEs Blog | G5 Cyber Security

CVE-2020-26958 – Firefox did not block execution of scripts with incorrect MIME types when

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.   Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26958 Reference (s):

Exit mobile version