CVE-2022-22744
published 2022-12-22CVE-2022-22744: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if…
PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.34%
68.2th percentile
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 96.0 | 96.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 96 | 96 |
| mozilla | firefox_esr | < 91.5 | 91.5 |
| mozilla | firefox_esr | >= unspecified < 91.5 | 91.5 |
| mozilla | thunderbird | < 91.5 | 91.5 |
| mozilla | thunderbird | >= unspecified < 91.5 | 91.5 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: The 'Copy as curl' feature in DevTools did not fully escape website-controlled data, potentially leading to command injection
vendor_redhat·2022-01-11·CVSS 8.8
CVE-2022-22744 [HIGH] CWE-77 Mozilla: The 'Copy as curl' feature in DevTools did not fully escape website-controlled data, potentially leading to command injection
Mozilla: The 'Copy as curl' feature in DevTools did not fully escape website-controlled data, potentially leading to command injection
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linu
Debian
CVE-2022-22744: firefox - The constructed curl command from the "Copy as curl" feature in DevTools was not...
vendor_debian·2022·CVSS 8.8
CVE-2022-22744 [HIGH] CVE-2022-22744: firefox - The constructed curl command from the "Copy as curl" feature in DevTools was not...
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2022-03: CVE-2022-22744
vendor_mozilla·CVSS 8.8
CVE-2022-22744 [HIGH] Mozilla Foundation Security Advisory 2022-03: CVE-2022-22744
Mozilla Foundation Security Advisory 2022-03
CVE: CVE-2022-22744
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 91.5
Mozilla
Mozilla Foundation Security Advisory 2022-02: CVE-2022-22744
vendor_mozilla·CVSS 8.8
CVE-2022-22744 [HIGH] Mozilla Foundation Security Advisory 2022-02: CVE-2022-22744
Mozilla Foundation Security Advisory 2022-02
CVE: CVE-2022-22744
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 91.5
Mozilla
Mozilla Foundation Security Advisory 2022-01: CVE-2022-22744
vendor_mozilla·CVSS 8.8
CVE-2022-22744 [HIGH] Mozilla Foundation Security Advisory 2022-01: CVE-2022-22744
Mozilla Foundation Security Advisory 2022-01
CVE: CVE-2022-22744
Product: Firefox
Impact: moderate
Fixed in: Firefox 96
GHSA
GHSA-4989-6q5w-wjgw: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell
ghsa_unreviewed·2022-12-22
CVE-2022-22744 [HIGH] CWE-116 GHSA-4989-6q5w-wjgw: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
OSV
CVE-2022-22744: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell
osv·2022-12-22·CVSS 8.8
CVE-2022-22744 [HIGH] CVE-2022-22744: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1737252https://www.mozilla.org/security/advisories/mfsa2022-01/https://www.mozilla.org/security/advisories/mfsa2022-02/https://www.mozilla.org/security/advisories/mfsa2022-03/https://bugzilla.mozilla.org/show_bug.cgi?id=1737252https://www.mozilla.org/security/advisories/mfsa2022-01/https://www.mozilla.org/security/advisories/mfsa2022-02/https://www.mozilla.org/security/advisories/mfsa2022-03/
2022-12-22
Published