#VU60399 Origin validation error in Mozilla Firefox - CVE-2022-22757
Published: February 8, 2022
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the Remote Agent, used in WebDriver, does not validate the Host or Origin headers. A remote website can force the browser to connect back locally to the user's browser to control it.
Successful exploitation of the vulnerability requires that WebDriver is enabled (not the default configuration).