CVE-2022-34469: High severity firefox vulnerability
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. This bug only affects Firefox for Android. Other operating systems are unaffected.
Other sources
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 102.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-34469?
CVE-2022-34469 is classified as a moderate severity vulnerability.
How do I fix CVE-2022-34469?
To fix CVE-2022-34469, update your Mozilla Firefox to version 102 or later.
What platforms are affected by CVE-2022-34469?
CVE-2022-34469 affects Firefox versions prior to 102 on Android devices.
What does CVE-2022-34469 exploit?
CVE-2022-34469 exploits the ability of users to bypass TLS Certificate errors on HSTS-protected domains.
Who is the vendor of the software impacted by CVE-2022-34469?
The vendor of the software impacted by CVE-2022-34469 is Mozilla.