First published: Tue May 31 2022(Updated: )
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <101 | 101 |
<101 | 101 | |
<91.11 | 91.11 | |
<102 | 102 | |
<91.11 | 91.11 | |
Mozilla Firefox | <101.0 | |
Mozilla Firefox ESR | <91.11 | |
Mozilla Thunderbird | <91.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2022-31744.
The title of the vulnerability is 'An attacker could have injected CSS into stylesheets accessible via internal URIs such as resource:'.
An attacker can exploit this vulnerability by injecting CSS into stylesheets accessible via internal URIs, such as resource:.
The software affected by this vulnerability includes Mozilla Firefox versions up to and excluding 101, Mozilla Thunderbird versions up to and excluding 102, Mozilla Thunderbird version 91.11, and Mozilla Firefox ESR version 91.11.
The severity of CVE-2022-31744 is medium with a CVSS score of 4.
To fix this vulnerability, update your Mozilla Firefox or Mozilla Thunderbird software to the specified versions or higher.