CVE-2022-22744: Command Injection
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.This bug only affects Firefox for Windows. Other operating systems are unaffected.
Other sources
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.This bug only affects Thunderbird for Windows. Other operating systems are unaffected.
— Mozilla
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>This bug only affects Thunderbird for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-22744?
CVE-2022-22744 is classified as a critical vulnerability due to its potential for command injection in PowerShell.
How do I fix CVE-2022-22744?
To mitigate CVE-2022-22744, users should upgrade to Firefox ESR version 91.5 or Firefox version 96 and ensure all software is updated.
Who is affected by CVE-2022-22744?
CVE-2022-22744 primarily affects Firefox and Thunderbird users on Windows operating systems.
What does CVE-2022-22744 exploit?
CVE-2022-22744 exploits the "Copy as curl" feature in DevTools where the constructed curl command is not properly escaped.
Is CVE-2022-22744 limited to specific versions?
Yes, CVE-2022-22744 affects Firefox versions up to 96 and Firefox ESR versions up to 91.5.