First published: Tue Jun 28 2022(Updated: )
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox ESR | <91.11 | 91.11 |
Thunderbird | <102 | 102 |
Thunderbird | <91.11 | 91.11 |
Firefox | <102.0 | |
Firefox ESR | <91.11 | |
Thunderbird | <91.11 | |
Firefox | <102 | 102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-34472 has been classified as a moderate severity vulnerability due to its impact on OCSP requests.
To fix CVE-2022-34472, update your Mozilla Firefox or Thunderbird to the latest version that is not affected by this vulnerability.
CVE-2022-34472 affects Mozilla Firefox ESR versions up to 91.11 and Mozilla Thunderbird versions up to 102.
The impact of CVE-2022-34472 includes blocked OCSP requests leading to incorrect error messages being displayed.
Currently, there are no documented workarounds for CVE-2022-34472 other than upgrading to a patched version.