CVE-2022-22760Information Exposure via Error Message in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.2%
top 56.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateMar 19

Description

When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified97
NVDmozilla/firefox< 97.0
CVEListV5mozilla/firefox_esrunspecified91.6
Ubuntumozilla/firefox< 97.0+build2-0ubuntu0.18.04.1+1

🔴Vulnerability Details

5
CVEList
CVE-2022-22760: When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script re2022-12-22
OSV
CVE-2022-22760: When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script re2022-12-22
GHSA
GHSA-mpq8-m953-pwhf: When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script re2022-12-22
OSV
thunderbird vulnerabilities2022-03-23
OSV
firefox vulnerabilities2022-02-14

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2022-03-23
Ubuntu
Firefox vulnerabilities2022-02-14
Red Hat
Mozilla: Cross-Origin responses could be distinguished between script and non-script content-types2022-02-08
Debian
CVE-2022-22760: firefox - When importing resources using Web Workers, error messages would distinguish the...2022
Mozilla
Mozilla Foundation Security Advisory 2022-05: CVE-2022-22760

💬Community

1
Bugzilla
Detect Content Script of Cross-Origin using worker load-error messages2024-03-19
CVE-2022-22760 — Information Exposure via Error Message | cvebase