First published: Tue Jan 11 2022(Updated: )
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.This bug only affects Firefox for Windows. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.5 | 91.5 |
<96 | 96 | |
<91.5 | 91.5 | |
<91.5 | 91.5 | |
Mozilla Firefox | <96.0 | |
Mozilla Firefox ESR | <91.5 | |
Mozilla Thunderbird | <91.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22744 is classified as a critical vulnerability due to its potential for command injection in PowerShell.
To mitigate CVE-2022-22744, users should upgrade to Firefox ESR version 91.5 or Firefox version 96 and ensure all software is updated.
CVE-2022-22744 primarily affects Firefox and Thunderbird users on Windows operating systems.
CVE-2022-22744 exploits the "Copy as curl" feature in DevTools where the constructed curl command is not properly escaped.
Yes, CVE-2022-22744 affects Firefox versions up to 96 and Firefox ESR versions up to 91.5.