OS Command Injection in Mozilla Firefox and Firefox ESR - CVE-2022-22744
Published: January 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the "Copy as curl" feature in DevTools. A remote attacker can trick the victim to cope a specially crafted link and execute arbitrary commands on the system, if copied data is pasted into a Powershell prompt.
Affected software
Firefox ESR
Pale Moon
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Desktop Applications
Mozilla Thunderbird
MozillaFirefox-debuginfo
MozillaFirefox-translations-other
MozillaFirefox-translations-common
MozillaFirefox
MozillaFirefox-devel
MozillaFirefox-debugsource
How to mitigate CVE-2022-22744
Firefox ESR - update to 91.5.0
Pale Moon - update to 29.4.4
Mozilla Thunderbird - update to 91.5.0
MozillaFirefox-debuginfo - addressed in versions 91.5.0-78.159.1, 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox-translations-other - addressed in versions 91.5.0-78.159.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox-translations-common - addressed in versions 91.5.0-78.159.1, 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox - addressed in versions 91.5.0-78.159.1, 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox-devel - addressed in versions 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1
MozillaFirefox-debugsource - addressed in versions 91.5.0-112.86.1, 91.5.0-150.15.1, 91.5.0-152.12.1