PT-2022-3465 · Mozilla+10 · Thunderbird+11

Gertjan

·

Published

2022-06-01

·

Updated

2024-12-12

·

CVE-2022-31744

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox ESR versions prior to 91.11 Thunderbird versions prior to 102 Thunderbird versions prior to 91.11 Firefox versions prior to 101
Description An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This issue is related to an error in processing CSS stylesheets accessible through internal URIs. Exploitation of this issue may allow a remote attacker to bypass the implemented Content Security Policy.
Recommendations For Firefox ESR versions prior to 91.11, update to version 91.11 or later. For Thunderbird versions prior to 102, update to version 102 or later. For Thunderbird versions prior to 91.11, update to version 91.11 or later. For Firefox versions prior to 101, update to version 101 or later. As a temporary workaround, consider disabling access to internal URIs, such as resource:, until a patch is available.

Exploit

Fix

Special Elements Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:5482
ALT-PU-2022-1988
ALT-PU-2022-2153
ALT-PU-2022-2458
ALT-PU-2022-2515
ALT-PU-2022-2929
ALT-PU-2022-2930
ALT-PU-2022-2931
ALT-PU-2023-1137
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4335
ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-04243
CESA-2022_5469
CESA-2022_5470
CESA-2022_5479
CESA-2022_5480
CVE-2022-31744
DLA-3064-1
DSA-5172-1
DSA-5175-1
MGASA-2022-0251
MGASA-2022-0253
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2022_2313-1
OPENSUSE-SU-2022_2320-1
OPENSUSE-SU-2022_3281-1
OPENSUSE-SU-2024:12121-1
OPENSUSE-SU-2024:12161-1
OPENSUSE-SU-2024:14572-1
RHSA-2022:5469
RHSA-2022:5470
RHSA-2022:5472
RHSA-2022:5473
RHSA-2022:5474
RHSA-2022:5475
RHSA-2022:5477
RHSA-2022:5478
RHSA-2022:5479
RHSA-2022:5480
RHSA-2022:5481
RHSA-2022:5482
RHSA-2022_5469
RHSA-2022_5470
RHSA-2022_5479
RHSA-2022_5480
RHSA-2022_5481
RHSA-2022_5482
RLSA-2022:5469
RLSA-2022:5470
SUSE-SU-2022:2279-1
SUSE-SU-2022:2289-1
SUSE-SU-2022:2313-1
SUSE-SU-2022:2320-1
SUSE-SU-2022:3281-1
USN-5475-1
USN-5512-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu