CVE-2022-28284: High severity firefox vulnerability
SVG's <code><use></code> element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs. This vulnerability affects Firefox < 99.
Other sources
SVG's <use> element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability CVE-2022-28284?
CVE-2022-28284 is a vulnerability in SVG's <use> element that could allow the loading of unexpected content and the execution of scripts in certain circumstances.
How does CVE-2022-28284 affect Mozilla Firefox?
CVE-2022-28284 affects Mozilla Firefox versions up to exclusive 99.0.
Is CVE-2022-28284 a high severity vulnerability?
Yes, CVE-2022-28284 has a high severity rating with a CVSS score of 8.8.
How can I fix CVE-2022-28284?
To fix CVE-2022-28284, update your Mozilla Firefox browser to version 99.0 or later.
Where can I find more information about CVE-2022-28284?
You can find more information about CVE-2022-28284 on the Mozilla website in the following links: [1] [2] [3]