Vulnerability Description
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 107.0 |
| Android | - |
Related Weaknesses (CWE)
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1791201Issue TrackingPermissions RequiredVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-47/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1791201Issue TrackingPermissions RequiredVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-47/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1791201Issue TrackingPermissions RequiredVendor Advisory
FAQ
What is CVE-2022-45413?
CVE-2022-45413 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Andr...
How severe is CVE-2022-45413?
CVE-2022-45413 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-45413?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Google Android.