CVE-2022-31739External Control of File Name or Path in Mozilla Firefox

Severity
8.8HIGHNVD
EPSS
0.5%
top 35.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22

Description

When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5mozilla/firefoxunspecified101
NVDmozilla/firefox< 101
CVEListV5mozilla/firefox_esrunspecified91.10
NVDmozilla/firefox_esr< 91.10
CVEListV5mozilla/thunderbirdunspecified91.10

🔴Vulnerability Details

3
GHSA
GHSA-w6x2-rcr6-2hh6: When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced2022-12-22
CVEList
CVE-2022-31739: When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced2022-12-22
OSV
CVE-2022-31739: When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced2022-12-22

📋Vendor Advisories

5
Red Hat
Mozilla: Attacker-influenced path traversal when saving downloaded files2022-05-31
Debian
CVE-2022-31739: firefox - When downloading files on Windows, the % character was not escaped, which could ...2022
Mozilla
Mozilla Foundation Security Advisory 2022-20: CVE-2022-31739
Mozilla
Mozilla Foundation Security Advisory 2022-22: CVE-2022-31739
Mozilla
Mozilla Foundation Security Advisory 2022-21: CVE-2022-31739
CVE-2022-31739 — External Control of File Name or Path | cvebase