CVE-2022-22760: Medium severity thunderbird vulnerability
When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Other sources
When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-22760?
CVE-2022-22760 is a vulnerability that affected Mozilla Firefox, Firefox ESR, and Thunderbird versions up to 91.6.
How does CVE-2022-22760 impact web workers?
CVE-2022-22760 allowed error messages when importing resources using web workers to distinguish between application/javascript responses and non-script responses, potentially leaking cross-origin information.
Which software versions are affected by CVE-2022-22760?
CVE-2022-22760 affected Mozilla Firefox versions up to 97, Firefox ESR versions up to 91.6, and Thunderbird versions up to 91.6.
What is the severity of CVE-2022-22760?
CVE-2022-22760 has a severity level of medium with a CVSS score of 4.
How can I fix CVE-2022-22760?
To fix CVE-2022-22760, update your Mozilla Firefox, Firefox ESR, or Thunderbird to version 91.6 (for Firefox ESR) or 97 (for Firefox).