CVE-2022-29909: High severity thunderbird vulnerability
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions.
Other sources
Documents in deeply-nested cross-origin browsing contexts could obtain permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-29909?
CVE-2022-29909 is considered to have high severity due to its potential to allow unauthorized permission inheritance in cross-origin contexts.
How do I fix CVE-2022-29909?
To mitigate CVE-2022-29909, update your Mozilla Firefox or Thunderbird to versions beyond 91.9 for ESR and 100 for standard releases.
What products are affected by CVE-2022-29909?
CVE-2022-29909 affects Mozilla Firefox up to version 100, Mozilla Firefox ESR up to version 91.9, and Mozilla Thunderbird up to version 91.9.
What kind of security risk does CVE-2022-29909 pose?
CVE-2022-29909 poses a security risk by potentially allowing documents in deeply-nested cross-origin browsing contexts to inherit permissions without prompts.
Can I check if my current Firefox version is vulnerable to CVE-2022-29909?
Yes, you can check your Firefox version under the 'About' section, and if it is below version 100, it is vulnerable to CVE-2022-29909.