PT-2022-6119 · Mozilla+4 · Firefox+5
Axel Chong
·
Published
2022-11-15
·
Updated
2024-12-12
·
CVE-2022-45413
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 107
Firefox for Android (affected versions not specified)
Description
The issue is related to the use of open redirection when handling the
S.browser fallback url parameter. An attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent, potentially allowing for a CSRF attack using a specially crafted web page. This issue only affects Firefox for Android, with other operating systems not being affected.Recommendations
For Firefox versions prior to 107, update to version 107 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the
S.browser fallback url parameter to minimize the risk of exploitation.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Firefox For Android
Linuxmint
Ubuntu