CVE-2022-46873: High severity firefox vulnerability
Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.
Other sources
Because Firefox did not implement the unsafe-hashes CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-46873?
CVE-2022-46873 is a vulnerability in Mozilla Firefox that allows an attacker to inject executable script into a page protected by Content Security Policy.
How does CVE-2022-46873 affect Firefox?
CVE-2022-46873 affects Mozilla Firefox versions up to and including version 108.0.
What is the severity of CVE-2022-46873?
CVE-2022-46873 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2022-46873?
An attacker can exploit CVE-2022-46873 by injecting markup into a page protected by Content Security Policy.
Are there any remedies or fixes for CVE-2022-46873?
Mozilla has released a fix for CVE-2022-46873 in Firefox version 108.0 and recommends updating to the latest version.