CVE-2022-31739: Path Traversal
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.This bug only affects Firefox for Windows. Other operating systems are unaffected.
Other sources
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.This bug only affects Thunderbird for Windows. Other operating systems are unaffected.
— Mozilla
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-31739?
CVE-2022-31739 is considered a moderate severity vulnerability.
How do I fix CVE-2022-31739?
To fix CVE-2022-31739, update Firefox, Firefox ESR, or Thunderbird to the latest version beyond 101 or 91.10 respectively.
Who is affected by CVE-2022-31739?
CVE-2022-31739 affects Firefox, Firefox ESR, and Thunderbird on Windows only.
What type of vulnerability is CVE-2022-31739?
CVE-2022-31739 is a file path manipulation vulnerability that could allow files to be downloaded to attacker-controlled paths.
Can CVE-2022-31739 affect other operating systems?
No, CVE-2022-31739 specifically affects only Windows versions of Firefox, Firefox ESR, and Thunderbird.