Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox ESR - CVE-2022-22746

 

Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox ESR - CVE-2022-22746

Published: January 11, 2022


Vulnerability identifier: #VU59366
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22746
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to a race condition when calling reportValidity. A remote attacker can trick the victim to open a specially crafted web page and bypass the fullscreen notification, which can lead to spoofing attack.


Affected software

Mozilla Firefox
Firefox ESR
Pale Moon
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Desktop Applications
Mozilla Thunderbird
MozillaFirefox-debuginfo
MozillaFirefox-translations-other
MozillaFirefox-translations-common
MozillaFirefox
MozillaFirefox-devel
MozillaFirefox-debugsource

How to mitigate CVE-2022-22746

Install updates from vendor's website.

Mozilla Firefox - update to 96.0
Firefox ESR - update to 91.5.0
Pale Moon - update to 29.4.4
Mozilla Thunderbird - update to 91.5.0
MozillaFirefox-debuginfo - addressed in versions 91.5.0-78.159.1, 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox-translations-other - addressed in versions 91.5.0-78.159.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox-translations-common - addressed in versions 91.5.0-78.159.1, 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox - addressed in versions 91.5.0-78.159.1, 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox-devel - addressed in versions 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox-debugsource - addressed in versions 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1

External References

Related Security Bulletins