Information disclosure in Mozilla Firefox - CVE-2022-29915
Published: May 3, 2022
Vulnerability identifier: #VU62762
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29915
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to performance API does not properly hide the fact whether a request cross-origin resource has observed redirects. A remote attacker can gain access to potentially sensitive information.
Affected software
Mozilla Firefox
Pale Moon
Arch Linux
Gentoo Linux
Ubuntu
firefox (Ubuntu package)
Pale Moon
Arch Linux
Gentoo Linux
Ubuntu
firefox (Ubuntu package)
How to mitigate CVE-2022-29915
Install updates from vendor's website.
Mozilla Firefox - update to 100.0
Pale Moon - update to 31.0.0
firefox (Ubuntu package) - addressed in versions 100.0+build2-0ubuntu0.18.04.1, 100.0+build2-0ubuntu0.20.04.1, 100.0+build2-0ubuntu0.21.10.1
Pale Moon - update to 31.0.0
firefox (Ubuntu package) - addressed in versions 100.0+build2-0ubuntu0.18.04.1, 100.0+build2-0ubuntu0.20.04.1, 100.0+build2-0ubuntu0.21.10.1