First published: Tue May 03 2022(Updated: )
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <91.9 | 91.9 |
Firefox | <100.0 | |
Firefox ESR | <91.9 | |
Thunderbird | <91.9 | |
Firefox | <100 | 100 |
Firefox ESR | <91.9 | 91.9 |
<100.0 | ||
<91.9 | ||
<91.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-29912 has a medium severity rating due to its potential impact on privacy and security.
To address CVE-2022-29912, update to Thunderbird version 91.9, Firefox ESR version 91.9, or Firefox version 100 or later.
CVE-2022-29912 affects Thunderbird versions earlier than 91.9, Firefox ESR versions earlier than 91.9, and Firefox versions earlier than 100.
CVE-2022-29912 is a privacy vulnerability linked to improper handling of cookies with the SameSite attribute.
There are no specific workarounds for CVE-2022-29912; upgrading to the recommended versions is advised.