Origin validation error in Mozilla Firefox - CVE-2022-22757

 

Origin validation error in Mozilla Firefox - CVE-2022-22757

Published: February 8, 2022


Vulnerability identifier: #VU60399
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-22757
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Mozilla
Affected software:
Mozilla Firefox

Detailed vulnerability description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to the Remote Agent, used in WebDriver, does not validate the Host or Origin headers. A remote website can force the browser to connect back locally to the user's browser to control it.

Successful exploitation of the vulnerability requires that WebDriver is enabled (not the default configuration).


How to mitigate CVE-2022-22757

Install updates from vendor's website.

Sources