CVE-2022-34474: Medium severity firefox vulnerability
Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102.
Other sources
Even when an iframe was sandboxed with allow-top-navigation-by-user-activation, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-34474.
What is the severity of CVE-2022-34474?
The severity of CVE-2022-34474 is medium with a CVSS score of 6.1.
Which browsers are affected by CVE-2022-34474?
Firefox versions up to and excluding 102 are affected by CVE-2022-34474.
How does CVE-2022-34474 impact sandboxed iframes with allow-top-navigation-by-user-activation?
Even when an iframe is sandboxed with allow-top-navigation-by-user-activation, if it receives a redirect header to an external protocol, the browser will process the redirect and prompt the user as appropriate.
How can I find more information about CVE-2022-34474?
You can find more information about CVE-2022-34474 in the following references: [1](https://bugzilla.mozilla.org/show_bug.cgi?id=1677138), [2](https://www.mozilla.org/en-US/security/advisories/mfsa2022-24/), [3](https://www.mozilla.org/security/advisories/mfsa2022-24/)