First published: Tue Jun 28 2022(Updated: )
The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <102 | 102 |
<102 | 102 | |
Mozilla Firefox | <102.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2022-34477.
This vulnerability affects Mozilla Firefox versions up to but excluding 102.
The severity of CVE-2022-34477 is high with a severity value of 7.5.
This vulnerability could enable XS-Leaks attacks by leaking information about same-site cross-origin resources in Mozilla Firefox.
To fix this vulnerability, update your Mozilla Firefox browser to version 102 or above.