First published: Tue Jul 26 2022(Updated: )
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <103 | 103 |
Firefox | <103.0 | |
<103.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-36316 is classified as a security vulnerability that could allow an attacker to infer information about redirects.
To address CVE-2022-36316, upgrade Mozilla Firefox to version 104 or later.
CVE-2022-36316 affects Mozilla Firefox versions up to and including 103.
CVE-2022-36316 can potentially allow attackers to learn about redirects, exposing sensitive information.
For more details on CVE-2022-36316, refer to Mozilla's security advisories.