First published: Tue Sep 20 2022(Updated: )
When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <102.3 | 102.3 |
<105 | 105 | |
<102.3 | 102.3 | |
<102.3 | 102.3 | |
Mozilla Firefox | <105.0 | |
Mozilla Firefox ESR | <102.3 | |
Mozilla Thunderbird | <102.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2022-40956.
The affected software includes Mozilla Thunderbird up to version 102.3, Mozilla Firefox ESR up to version 102.3, and Mozilla Firefox up to version 105.
CVE-2022-40956 has a low severity level.
When injecting an HTML base element, some requests may ignore the CSP's base-uri settings and accept the injected element's base instead.
The remedy for this vulnerability is to update to Mozilla Thunderbird version 102.3 or later, Mozilla Firefox ESR version 102.3 or later, or Mozilla Firefox version 105 or later.