First published: Tue Nov 15 2022(Updated: )
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <107.0 | |
Google Android | ||
Mozilla Firefox | <107 | 107 |
All of | ||
Mozilla Firefox | <107.0 | |
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-45413 is a vulnerability that allows an attacker to redirect a user and potentially expose SameSite=Strict cookies in Firefox for Android version 107.
Firefox version up to 107 is affected by CVE-2022-45413, specifically on Firefox for Android.
CVE-2022-45413 can be exploited by an attacker to redirect a user to a malicious URL, potentially exposing SameSite=Strict cookies.
CVE-2022-45413 has a severity rating of 6.1 (medium).
To mitigate CVE-2022-45413, users can update to the latest version of Firefox for Android, which has the fix applied.