First published: Tue May 03 2022(Updated: )
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <91.9 | 91.9 |
Firefox | <100.0 | |
Firefox ESR | <91.9 | |
Thunderbird | <91.9 | |
Firefox | <100 | 100 |
Firefox ESR | <91.9 | 91.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-29909 is considered to have high severity due to its potential to allow unauthorized permission inheritance in cross-origin contexts.
To mitigate CVE-2022-29909, update your Mozilla Firefox or Thunderbird to versions beyond 91.9 for ESR and 100 for standard releases.
CVE-2022-29909 affects Mozilla Firefox up to version 100, Mozilla Firefox ESR up to version 91.9, and Mozilla Thunderbird up to version 91.9.
CVE-2022-29909 poses a security risk by potentially allowing documents in deeply-nested cross-origin browsing contexts to inherit permissions without prompts.
Yes, you can check your Firefox version under the 'About' section, and if it is below version 100, it is vulnerable to CVE-2022-29909.