#VU60399 Origin validation error in Mozilla Firefox - CVE-2022-22757

 

#VU60399 Origin validation error in Mozilla Firefox - CVE-2022-22757

Published: February 8, 2022


Vulnerability identifier: #VU60399
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-22757
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to the Remote Agent, used in WebDriver, does not validate the Host or Origin headers. A remote website can force the browser to connect back locally to the user's browser to control it.

Successful exploitation of the vulnerability requires that WebDriver is enabled (not the default configuration).


Remediation

Install updates from vendor's website.

External links