#VU69334 Security features bypass in Mozilla Firefox and Firefox for Android - CVE-2022-45419
Published: November 15, 2022
Mozilla Firefox
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the way Firefox handles deletion of a security exception granted for an invalid TLS certificate. If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted.