PT-2022-6119 · Mozilla+4 · Firefox+5

Axel Chong

·

Published

2022-11-15

·

Updated

2024-12-12

·

CVE-2022-45413

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 107 Firefox for Android (affected versions not specified)
Description The issue is related to the use of open redirection when handling the S.browser fallback url parameter. An attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent, potentially allowing for a CSRF attack using a specially crafted web page. This issue only affects Firefox for Android, with other operating systems not being affected.
Recommendations For Firefox versions prior to 107, update to version 107 or later to resolve the issue. As a temporary workaround, consider restricting the use of the S.browser fallback url parameter to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3090
ALT-PU-2022-3270
ALT-PU-2023-5754
ALT-PU-2023-6436
BDU:2023-00059
CVE-2022-45413
OPENSUSE-SU-2024:12518-1
OPENSUSE-SU-2024:14572-1
USN-5726-1

Affected Products

Alt Linux
Astra Linux
Firefox
Firefox For Android
Linuxmint
Ubuntu