PT-2022-3564 · Mozilla+4 · Firefox+4

Sohom Datta

·

Published

2022-05-03

·

Updated

2024-12-12

·

CVE-2022-29915

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 100
Description The Performance API in Firefox did not properly hide whether a request for a cross-origin resource has observed redirects, leading to a potential information disclosure. This issue may allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 100, update to version 100 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Exploit

Fix

Information Disclosure

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1812
ALT-PU-2022-2458
ALT-PU-2022-2929
ALT-PU-2022-2930
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-04348
CVE-2022-29915
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2024:12044-1
OPENSUSE-SU-2024:14572-1
USN-5411-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu