First published: Tue Dec 13 2022(Updated: )
Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <108 | 108 |
<108 | 108 | |
Mozilla Firefox | <108.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-46873 is a vulnerability in Mozilla Firefox that allows an attacker to inject executable script into a page protected by Content Security Policy.
CVE-2022-46873 affects Mozilla Firefox versions up to and including version 108.0.
CVE-2022-46873 has a severity rating of 8.8 (high).
An attacker can exploit CVE-2022-46873 by injecting markup into a page protected by Content Security Policy.
Mozilla has released a fix for CVE-2022-46873 in Firefox version 108.0 and recommends updating to the latest version.