CVE-2022-34468: High severity firefox esr vulnerability
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Other sources
An iframe that was not permitted to run scripts could do so if the user clicked on a javascript: link.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-34468?
CVE-2022-34468 is classified as a moderate severity vulnerability.
How do I fix CVE-2022-34468?
To fix CVE-2022-34468, update to Mozilla Firefox version 102 or later, or Firefox ESR version 91.11 or later.
Which products are affected by CVE-2022-34468?
CVE-2022-34468 affects Firefox versions prior to 102, Firefox ESR versions prior to 91.11, and Thunderbird versions prior to 102.
What type of attack is CVE-2022-34468 associated with?
CVE-2022-34468 is associated with an iframe script execution vulnerability that can be exploited through user interaction.
Who is the vendor responsible for CVE-2022-34468?
The vendor responsible for CVE-2022-34468 is Mozilla.