CVE-2024-0310: Trellix Endpoint Security Web Control
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.
Affected products
- Trellix Endpoint Security Web Control: before 10.7.0 (fixed in 10.7.0); version 10.7.0 only
Published 2024-01-10. Last modified 2026-06-17.