Hide Forgot
NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value. References: https://noscript.net/getit#classic https://www.zdnet.com/article/exploit-vendor-drops-tor-browser-zero-day-on-twitter/
Created mozilla-noscript tracking bugs for this issue: Affects: epel-all [bug 1629217]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.