Origin validation error in Mozilla Firefox - CVE-2022-22757

 

Origin validation error in Mozilla Firefox - CVE-2022-22757

Published: February 8, 2022


Vulnerability identifier: #VU60399
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22757
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to the Remote Agent, used in WebDriver, does not validate the Host or Origin headers. A remote website can force the browser to connect back locally to the user's browser to control it.

Successful exploitation of the vulnerability requires that WebDriver is enabled (not the default configuration).


Affected software

Mozilla Firefox
Gentoo Linux
Ubuntu
firefox (Ubuntu package)

How to mitigate CVE-2022-22757

Install updates from vendor's website.

Mozilla Firefox - update to 97.0
firefox (Ubuntu package) - addressed in versions 97.0+build2-0ubuntu0.18.04.1, 97.0+build2-0ubuntu0.20.04.1, 97.0+build2-0ubuntu0.21.10.1

External References

Related Security Bulletins