CVE-2017-5466 - log back

CVE-2017-5466 created at 25 Sep 2019 19:31:40
Severity
+ Critical
Remote
+ Remote
Type
+ Cross-site scripting
Description
+ An origin confusion issue has been found in Firefox < 53. If a page is loaded from an original site through a hyperlink and contains a redirect to a data:text/html URL, triggering a reload will run the reloaded data:text/html page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5466
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1353975
Notes