Vulnerability Description
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 103.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1768583Issue TrackingPermissions RequiredVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-28/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1768583Issue TrackingPermissions RequiredVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-28/Vendor Advisory
FAQ
What is CVE-2022-36316?
CVE-2022-36316 is a vulnerability with a CVSS score of 6.1 (MEDIUM). When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability af...
How severe is CVE-2022-36316?
CVE-2022-36316 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36316?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox.