First published: Wed Jun 29 2022(Updated: )
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <102.0 | |
All of | ||
Firefox | =102 | |
Apple iOS and iPadOS | ||
<102.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31746 is classified as a moderate severity vulnerability due to the potential exposure of internal URLs.
To mitigate CVE-2022-31746, users should update Firefox for iOS to version 102.0 or later.
CVE-2022-31746 can be exploited through leaked UUID keys in the Referrer header that may reveal internal URLs.
CVE-2022-31746 affects Firefox for iOS versions prior to 102.0.
CVE-2022-31746 specifically impacts Firefox running on iOS devices.