First published: Tue May 31 2022(Updated: )
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.This bug only affects Firefox for Windows. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <101 | |
Firefox ESR | <91.10 | |
Thunderbird | <91.10 | |
Microsoft Windows | ||
Thunderbird | <91.10 | 91.10 |
Firefox | <101 | 101 |
Firefox ESR | <91.10 | 91.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-31739 is considered a moderate severity vulnerability.
To fix CVE-2022-31739, update Firefox, Firefox ESR, or Thunderbird to the latest version beyond 101 or 91.10 respectively.
CVE-2022-31739 affects Firefox, Firefox ESR, and Thunderbird on Windows only.
CVE-2022-31739 is a file path manipulation vulnerability that could allow files to be downloaded to attacker-controlled paths.
No, CVE-2022-31739 specifically affects only Windows versions of Firefox, Firefox ESR, and Thunderbird.