CVE-2018-5164

Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60. Date published : 2018-06-11 http://www.securityfocus.com/bid/104139

https://bugzilla.mozilla.org/show_bug.cgi?id=1416045