Loading HuntDB...

GHSA-6h7p-w66v-f7vw

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle attacks on the linked resources. This vulnerability affects Firefox < 66.

Related CVEs

Key Information

GHSA ID
GHSA-6h7p-w66v-f7vw
Published
May 24, 2022 4:44 PM
Last Modified
April 4, 2024 12:13 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.