CVE-2022-32308: XSS
Published Jul 13, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitrary code via a spoofed 'MessageSender.url' to the browser renderer process.
Affected Software
1 affected component
Ublock Origin Project Ublock Origin<1.41.1
Remediation
Patch Available
Event History
Jul 13, 2022
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-32308?
CVE-2022-32308 is categorized with a medium severity level due to its potential for allowing arbitrary code execution.
2
How do I fix CVE-2022-32308?
To fix CVE-2022-32308, update the uBlock Origin extension to version 1.41.1 or later.
3
Which versions of uBlock Origin are affected by CVE-2022-32308?
CVE-2022-32308 affects all versions of uBlock Origin prior to 1.41.1.
4
What type of vulnerability is CVE-2022-32308?
CVE-2022-32308 is a Cross Site Scripting (XSS) vulnerability.
5
What can an attacker do with CVE-2022-32308?
An attacker can exploit CVE-2022-32308 to run arbitrary code in the browser renderer process.