Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-34471

Опубликовано: 22 дек. 2022
Источник: debian
EPSS Низкий

Описание

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed102.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-24/#CVE-2022-34471

EPSS

Процентиль: 37%
0.00158
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

CVSS3: 6.5
nvd
почти 3 года назад

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

CVSS3: 6.5
github
почти 3 года назад

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

suse-cvrf
около 3 лет назад

Security update for MozillaFirefox

suse-cvrf
около 3 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 37%
0.00158
Низкий