#VU64759 Reliance on Untrusted Inputs in a Security Decision in Mozilla Firefox - CVE-2022-34471

 

#VU64759 Reliance on Untrusted Inputs in a Security Decision in Mozilla Firefox - CVE-2022-34471

Published: June 29, 2022


Vulnerability identifier: #VU64759
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-34471
CWE-ID: CWE-807
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to force downgrade existing browser addons.

The vulnerability exists due to missing verification of the advertised version when installing addon updates. When downloading an update for an addon, the downloaded addon update's version is not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version.


Remediation

Install updates from vendor's website.

External links