First published: Tue Apr 05 2022(Updated: )
SVG's <code><use></code> element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs. This vulnerability affects Firefox < 99.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <99 | 99 |
Firefox | <99.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-28284 is a vulnerability in SVG's <use> element that could allow the loading of unexpected content and the execution of scripts in certain circumstances.
CVE-2022-28284 affects Mozilla Firefox versions up to exclusive 99.0.
Yes, CVE-2022-28284 has a high severity rating with a CVSS score of 8.8.
To fix CVE-2022-28284, update your Mozilla Firefox browser to version 99.0 or later.
You can find more information about CVE-2022-28284 on the Mozilla website in the following links: [1] [2] [3]