First published: Tue May 31 2022(Updated: )
Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <101 | 101 |
Firefox | <101.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-31743 has a moderate severity rating due to the potential for HTML comment escaping.
To remediate CVE-2022-31743, upgrade to Mozilla Firefox version 101 or later.
CVE-2022-31743 can lead to XSS vulnerabilities by allowing attackers to manipulate HTML comments.
CVE-2022-31743 affects all versions of Mozilla Firefox prior to version 101.
There is no known workaround for CVE-2022-31743 other than upgrading to a secure version of Firefox.