PT-2022-4251 · Mozilla+4 · Firefox+4
Leo Balter
·
Published
2022-04-05
·
Updated
2024-12-12
·
CVE-2022-28284
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 99
Description
The issue is related to the implementation of the SVG
<use> element, which could be used to load unexpected content, potentially executing scripts under certain circumstances. Although the specification appears to permit this behavior, other browsers do not, and web developers have relied on this property for script security. As a result, Gecko's implementation was adjusted to align with other browsers.Recommendations
For Firefox versions prior to 99, update to version 99 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
<use> element in SVG content until the update is applied.Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu