CVE-2019-11737: Mozilla Firefox

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.

Affected products

  • Mozilla Firefox: before 69.0 (fixed in 69.0)

Published 2019-09-27. Last modified 2026-06-17.