PT-2022-4994 · Mozilla+10 · Thunderbird+12

Satoki Tsuji

·

Published

2022-09-20

·

Updated

2024-12-12

·

CVE-2022-40956

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 105 Firefox ESR versions prior to 102.3 Thunderbird versions prior to 102.3
Description The issue is related to an incorrect restriction of visualizable layers or frames in the user interface when handling HTML elements, specifically with the implementation of the Content Security Policy (CSP) base-uri directive in browsers. This can allow a remote attacker to bypass security restrictions by injecting an HTML base element, which some requests would accept instead of the CSP's base-uri settings.
Recommendations For Firefox versions prior to 105, update to version 105 or later to resolve the issue. For Firefox ESR versions prior to 102.3, update to version 102.3 or later to resolve the issue. For Thunderbird versions prior to 102.3, update to version 102.3 or later to resolve the issue.

Exploit

Fix

Clickjacking

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:6700
ALSA-2022:6702
ALSA-2022:6708
ALSA-2022:6717
ALT-PU-2022-2653
ALT-PU-2022-2747
ALT-PU-2022-2752
ALT-PU-2022-2930
ALT-PU-2022-3045
ALT-PU-2022-3046
ALT-PU-2023-1137
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4335
ALT-PU-2023-4336
ALT-PU-2023-4339
ALT-PU-2023-5754
ALT-PU-2024-3614
BDU:2022-06198
CESA-2022_6702
CESA-2022_6708
CVE-2022-40956
DLA-3121-1
DLA-3123-1
DSA-5237-1
DSA-5238-1
MGASA-2022-0344
MGASA-2022-0347
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2022_3396-1
OPENSUSE-SU-2022_3800-1
OPENSUSE-SU-2024:12358-1
OPENSUSE-SU-2024:12398-1
OPENSUSE-SU-2024:12425-1
OPENSUSE-SU-2024:14572-1
RHSA-2022:6700
RHSA-2022:6701
RHSA-2022:6702
RHSA-2022:6703
RHSA-2022:6707
RHSA-2022:6708
RHSA-2022:6710
RHSA-2022:6711
RHSA-2022:6713
RHSA-2022:6715
RHSA-2022:6716
RHSA-2022:6717
RHSA-2022_6700
RHSA-2022_6702
RHSA-2022_6708
RHSA-2022_6710
RHSA-2022_6711
RHSA-2022_6717
RLSA-2022:6702
RLSA-2022:6708
SUSE-SU-2022:3396-1
SUSE-SU-2022:3440-1
SUSE-SU-2022:3441-1
SUSE-SU-2022:3800-1
SUSE-SU-2022_3440-1
SUSE-SU-2022_3441-1
USN-5649-1
USN-5724-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu