First published: Tue Feb 08 2022(Updated: )
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*. This vulnerability affects Firefox < 97.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <97 | 97 |
<97 | 97 | |
Mozilla Firefox | <97.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22757 is considered to be of moderate severity due to its potential for remote code execution under specific circumstances.
To fix CVE-2022-22757, users should update to the latest version of Mozilla Firefox beyond version 97.
CVE-2022-22757 primarily affects users of Mozilla Firefox version 97 or earlier when WebDriver is enabled.
CVE-2022-22757 is a web security vulnerability related to improper validation of Host or Origin headers in WebDriver.
Yes, CVE-2022-22757 could potentially allow unauthorized access to the user's browser, leading to data breaches.