When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:10074 https://access.redhat.com/errata/RHSA-2025:10074
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:10073 https://access.redhat.com/errata/RHSA-2025:10073
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:10072 https://access.redhat.com/errata/RHSA-2025:10072
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:10182 https://access.redhat.com/errata/RHSA-2025:10182
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:10181 https://access.redhat.com/errata/RHSA-2025:10181
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:10184 https://access.redhat.com/errata/RHSA-2025:10184
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:10183 https://access.redhat.com/errata/RHSA-2025:10183
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:10187 https://access.redhat.com/errata/RHSA-2025:10187
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:10185 https://access.redhat.com/errata/RHSA-2025:10185
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:10186 https://access.redhat.com/errata/RHSA-2025:10186
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:10188 https://access.redhat.com/errata/RHSA-2025:10188