PT-2022-11569 · Mozilla+1 · Firefox+1
Rohan Sharma
·
Published
2022-12-22
·
Updated
2023-07-11
·
CVE-2021-4221
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 92
Description
The issue arises when a domain name contains a Right-to-Left (RTL) character, causing the domain to be rendered to the right of the path. This can lead to user confusion and potentially facilitate spoofing attacks. The bug specifically affects Firefox for Android, with other operating systems being unaffected.
Recommendations
For versions prior to 92, update to version 92 or later to resolve the issue. As a temporary workaround, consider avoiding the use of domain names with RTL characters in Firefox for Android until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox