#VU64759 Reliance on Untrusted Inputs in a Security Decision in Mozilla Firefox - CVE-2022-34471
Published: June 29, 2022
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to force downgrade existing browser addons.
The vulnerability exists due to missing verification of the advertised version when installing addon updates. When downloading an update for an addon, the downloaded addon update's version is not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version.