CVE-2022-22745: Infoleak
Published Jan 11, 2022
·Updated
Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations
Affected Software
6 affected componentsFixes available
Mozilla Thunderbird<91.5
91.5
Mozilla Firefox<96.0
Mozilla Firefox ESR<91.5
Mozilla Thunderbird<91.5
Mozilla Firefox<96
96
Mozilla Firefox ESR<91.5
91.5
Event History
Jan 11, 2022
CVE Published
via Mozilla·12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2022-22745.
2
What is the severity of CVE-2022-22745?
The severity of CVE-2022-22745 is medium.
3
Which software is affected by CVE-2022-22745?
Mozilla Firefox ESR (up to version 91.5), Thunderbird (up to version 91.5), and Firefox (up to version 96) are affected by CVE-2022-22745.
4
How can cross-origin information be leaked through CVE-2022-22745?
Cross-origin information can be leaked through CVE-2022-22745 via Securitypolicyviolation events for frame-ancestors violations.
5
Where can I find more information about CVE-2022-22745?
You can find more information about CVE-2022-22745 on the Mozilla Bugzilla and Mozilla Security Advisories websites.