PT-2022-4251 · Mozilla+4 · Firefox+4

Leo Balter

·

Published

2022-04-05

·

Updated

2024-12-12

·

CVE-2022-28284

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 99
Description The issue is related to the implementation of the SVG <use> element, which could be used to load unexpected content, potentially executing scripts under certain circumstances. Although the specification appears to permit this behavior, other browsers do not, and web developers have relied on this property for script security. As a result, Gecko's implementation was adjusted to align with other browsers.
Recommendations For Firefox versions prior to 99, update to version 99 or later to resolve the issue. As a temporary workaround, consider restricting the use of the <use> element in SVG content until the update is applied.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1642
ALT-PU-2022-2458
ALT-PU-2022-2929
ALT-PU-2022-2930
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-05101
CVE-2022-28284
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2024:11975-1
OPENSUSE-SU-2024:14572-1
USN-5370-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu