First published: Tue May 03 2022(Updated: )
Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <91.9 | 91.9 |
Firefox | <100.0 | |
Firefox ESR | <91.9 | |
Thunderbird | <91.9 | |
Firefox | <100 | 100 |
Firefox ESR | <91.9 | 91.9 |
<100.0 | ||
<91.9 | ||
<91.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2022-29916 is classified as moderate.
To fix CVE-2022-29916, users should update Firefox to version 100 or later for general releases and to Firefox ESR version 91.9 or later.
CVE-2022-29916 affects Mozilla Firefox versions up to 100, Mozilla Firefox ESR versions up to 91.9, and Mozilla Thunderbird versions up to 91.9.
Yes, CVE-2022-29916 can be exploited to potentially probe and leak browser history.
CVE-2022-29916 can be exploited via a remote attack if the user visits a malicious website.