First published: Tue Mar 08 2022(Updated: )
If an attacker could control the contents of an iframe sandboxed with `allow-popups` but not `allow-scripts`, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. External Reference: <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2022-11/#CVE-2022-26384">https://www.mozilla.org/en-US/security/advisories/mfsa2022-11/#CVE-2022-26384</a>
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.7 | 91.7 |
<98 | 98 | |
<91.7 | 91.7 | |
<91.7 | 91.7 | |
redhat/firefox | <0:91.7.0-3.el7_9 | 0:91.7.0-3.el7_9 |
redhat/thunderbird | <0:91.7.0-2.el7_9 | 0:91.7.0-2.el7_9 |
redhat/firefox | <0:91.7.0-3.el8_5 | 0:91.7.0-3.el8_5 |
redhat/thunderbird | <0:91.7.0-2.el8_5 | 0:91.7.0-2.el8_5 |
redhat/firefox | <0:91.7.0-3.el8_1 | 0:91.7.0-3.el8_1 |
redhat/thunderbird | <0:91.7.0-2.el8_1 | 0:91.7.0-2.el8_1 |
redhat/firefox | <0:91.7.0-3.el8_2 | 0:91.7.0-3.el8_2 |
redhat/thunderbird | <0:91.7.0-2.el8_2 | 0:91.7.0-2.el8_2 |
redhat/firefox | <0:91.7.0-3.el8_4 | 0:91.7.0-3.el8_4 |
redhat/thunderbird | <0:91.7.0-2.el8_4 | 0:91.7.0-2.el8_4 |
redhat/firefox | <91.7 | 91.7 |
redhat/thunderbird | <91.7 | 91.7 |
Mozilla Firefox | <98.0 | |
Mozilla Firefox ESR | <91.7 | |
Mozilla Thunderbird | <91.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The severity of CVE-2022-26384 is critical.
Firefox versions less than 98 and Firefox ESR versions less than 91.7 are affected by CVE-2022-26384. Additionally, Red Hat packages for Firefox and Thunderbird versions less than 91.7 are also affected.
An attacker can exploit CVE-2022-26384 by controlling the contents of an iframe sandboxed with allow-popups but not allow-scripts, and crafting a link that leads to JavaScript execution in violation of the sandbox.
To remediate CVE-2022-26384, update Firefox to version 98 or later, or update Firefox ESR to version 91.7 or later. Red Hat users should update the Firefox and Thunderbird packages to version 91.7 or later.
You can find more information about CVE-2022-26384 on the Mozilla Security Advisories page and the Bugzilla report.