First published: Tue Jun 28 2022(Updated: )
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.11 | 91.11 |
<102 | 102 | |
<91.11 | 91.11 | |
<102 | 102 | |
<91.11 | 91.11 | |
Mozilla Firefox | <102.0 | |
Mozilla Firefox ESR | <91.11 | |
Mozilla Thunderbird | <91.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2022-2200 is medium.
CVE-2022-2200 impacts Mozilla Firefox ESR versions up to and excluding 91.11.
CVE-2022-2200 impacts Mozilla Thunderbird versions up to and excluding 102.
An attacker can exploit CVE-2022-2200 by corrupting the object prototype, allowing them to set undesired attributes on JavaScript objects and leading to privileged code execution.
You can find more information about CVE-2022-2200 at the following references: [1] [2] [3].