First published: Tue Feb 08 2022(Updated: )
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.6 | 91.6 |
<97 | 97 | |
<91.6 | 91.6 | |
<91.6 | 91.6 | |
Mozilla Firefox | <97.0 | |
Mozilla Firefox ESR | <91.6 | |
Mozilla Thunderbird | <91.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22761 has been classified as a high severity vulnerability due to improper enforcement of security policies.
To mitigate CVE-2022-22761, update to Mozilla Firefox version 97 or later, or Mozilla Firefox ESR version 91.6 or later.
CVE-2022-22761 affects Mozilla Firefox, Firefox ESR, and Thunderbird versions below 97 and 91.6 respectively.
CVE-2022-22761 involves web-accessible extension pages not properly enforcing the frame-ancestors directive in Content Security Policy.
Yes, CVE-2022-22761 can increase the risk of cross-site scripting attacks due to the lack of proper security policy enforcement.