If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1561056 | vendor advisory issue tracking exploit |
https://www.mozilla.org/security/advisories/mfsa2019-34/ | vendor advisory |