First published: Tue Feb 08 2022(Updated: )
When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.6 | 91.6 |
<97 | 97 | |
<91.6 | 91.6 | |
<91.6 | 91.6 | |
Mozilla Firefox | <97.0 | |
Mozilla Firefox ESR | <91.6 | |
Mozilla Thunderbird | <91.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22760 is a vulnerability that affected Mozilla Firefox, Firefox ESR, and Thunderbird versions up to 91.6.
CVE-2022-22760 allowed error messages when importing resources using web workers to distinguish between application/javascript responses and non-script responses, potentially leaking cross-origin information.
CVE-2022-22760 affected Mozilla Firefox versions up to 97, Firefox ESR versions up to 91.6, and Thunderbird versions up to 91.6.
CVE-2022-22760 has a severity level of medium with a CVSS score of 4.
To fix CVE-2022-22760, update your Mozilla Firefox, Firefox ESR, or Thunderbird to version 91.6 (for Firefox ESR) or 97 (for Firefox).