First published: Tue Feb 08 2022(Updated: )
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.6 | 91.6 |
<97 | 97 | |
<91.6 | 91.6 | |
<91.6 | 91.6 | |
Mozilla Firefox | <97.0 | |
Mozilla Firefox ESR | <91.6 | |
Mozilla Thunderbird | <91.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2022-22754.
This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
The severity of CVE-2022-22754 is high with a CVSS score of 6.5.
To fix the vulnerability in Firefox, update to version 97 or later.
To fix the vulnerability in Thunderbird, update to version 91.6 or later.
To fix the vulnerability in Firefox ESR, update to version 91.6 or later.