First published: Tue Jun 28 2022(Updated: )
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox ESR | <91.11 | 91.11 |
Thunderbird | <102 | 102 |
Thunderbird | <91.11 | 91.11 |
Firefox | <102.0 | |
Firefox ESR | <91.11 | |
Thunderbird | <91.11 | |
Firefox | <102 | 102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-34468 is classified as a moderate severity vulnerability.
To fix CVE-2022-34468, update to Mozilla Firefox version 102 or later, or Firefox ESR version 91.11 or later.
CVE-2022-34468 affects Firefox versions prior to 102, Firefox ESR versions prior to 91.11, and Thunderbird versions prior to 102.
CVE-2022-34468 is associated with an iframe script execution vulnerability that can be exploited through user interaction.
The vendor responsible for CVE-2022-34468 is Mozilla.