CVE-2022-45403: Medium severity thunderbird vulnerability
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-45403?
CVE-2022-45403 is a vulnerability that allows Service Workers to infer information about opaque cross-origin responses, potentially leading to the determination of the presence or length of a media file.
What software is affected by CVE-2022-45403?
CVE-2022-45403 affects Firefox ESR versions prior to 102.5, Thunderbird versions prior to 102.5, and Firefox versions prior to 107.0.
How can this vulnerability be exploited?
This vulnerability can be exploited by Service Workers combined with Range requests and timing information for cross-origin media.
What is the severity of CVE-2022-45403?
CVE-2022-45403 has a severity rating of 6.5 (high).
How can I fix CVE-2022-45403?
To fix CVE-2022-45403, update Firefox ESR to version 102.5 or later, Thunderbird to version 102.5 or later, or Firefox to version 107.0 or later.