First published: Tue Nov 15 2022(Updated: )
Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <102.5 | 102.5 |
Mozilla Firefox ESR | <102.5 | 102.5 |
Mozilla Firefox | <107 | 107 |
Mozilla Firefox | <107.0 | |
Mozilla Firefox ESR | <102.5 | |
Mozilla Thunderbird | <102.5 | |
<107.0 | ||
<102.5 | ||
<102.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2022-45420.
The vulnerability could allow an attacker to render iframe contents outside of the boundaries, potentially leading to user confusion or spoofing attacks.
Firefox ESR versions earlier than 102.5, Thunderbird versions earlier than 102.5, and Firefox versions earlier than 107 are affected.
The severity of CVE-2022-45420 is rated as medium with a CVSS score of 6.5.
Update Firefox ESR to version 102.5 or later, Thunderbird to version 102.5 or later, and Firefox to version 107 or later to mitigate the vulnerability.