⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2022-1802Prototype Pollution in Mozilla Firefox

Severity
8.8HIGHNVD
EPSS
67.9%
top 1.41%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedDec 22

Description

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

CVEListV5mozilla/firefox_for_androidunspecified100.3.0
CVEListV5mozilla/firefoxunspecified100.0.2
NVDmozilla/firefox< 100.0.2+1
CVEListV5mozilla/firefox_esrunspecified91.9.1
NVDmozilla/firefox_esr< 91.9.1

🔴Vulnerability Details

4
OSV
CVE-2022-1802: If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacke2022-12-22
GHSA
GHSA-p859-wprc-3cjx: If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacke2022-12-22
CVEList
CVE-2022-1802: If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacke2022-12-22
VulnCheck
Mozilla Firefox Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')2022

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2022-05-25
Ubuntu
Firefox vulnerabilities2022-05-23
Red Hat
Mozilla: Prototype pollution in Top-Level Await implementation2022-05-20
Debian
CVE-2022-1802: firefox - If an attacker was able to corrupt the methods of an Array object in JavaScript ...2022
Mozilla
Mozilla Foundation Security Advisory 2022-19: CVE-2022-1802
CVE-2022-1802 — Prototype Pollution in Mozilla Firefox | cvebase