CVE-2022-40956: XSS
When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-40956.
What software is affected by this vulnerability?
The affected software includes Mozilla Thunderbird up to version 102.3, Mozilla Firefox ESR up to version 102.3, and Mozilla Firefox up to version 105.
What is the severity level of CVE-2022-40956?
CVE-2022-40956 has a low severity level.
What is the impact of this vulnerability?
When injecting an HTML base element, some requests may ignore the CSP's base-uri settings and accept the injected element's base instead.
Are there any remediation steps available for this vulnerability?
The remedy for this vulnerability is to update to Mozilla Thunderbird version 102.3 or later, Mozilla Firefox ESR version 102.3 or later, or Mozilla Firefox version 105 or later.