CVE-2022-31742: Medium severity thunderbird vulnerability
An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-31742?
CVE-2022-31742 has been classified with a severity level that may allow for potential cross-origin account linking exploits.
How do I fix CVE-2022-31742?
To remediate CVE-2022-31742, update affected Mozilla products such as Firefox, Firefox ESR, and Thunderbird to fixed versions 101 or 91.10.
Which software is affected by CVE-2022-31742?
CVE-2022-31742 affects Mozilla Firefox versions earlier than 101, Firefox ESR versions earlier than 91.10, and Thunderbird versions earlier than 91.10.
What types of attacks are associated with CVE-2022-31742?
CVE-2022-31742 is associated with timing attacks that could exploit vulnerabilities in handling allowCredential entries.
What are the potential consequences of CVE-2022-31742?
The exploitation of CVE-2022-31742 could lead to cross-origin account linking, undermining WebAuthn goals.