CVE-2022-31743Cross-site Scripting in Mozilla Firefox

Severity
6.5MEDIUMNVD
EPSS
0.6%
top 30.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22

Description

Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

debiandebian/firefox< firefox 101.0-1 (sid)
CVEListV5mozilla/firefoxunspecified101
NVDmozilla/firefox< 101.0
Ubuntumozilla/firefox< 101.0.1+build1-0ubuntu0.18.04.1+1
mozillamozilla/firefox

🔴Vulnerability Details

2
GHSA
GHSA-6wvv-23hx-p89r: Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers2022-12-22
OSV
CVE-2022-31743: Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers2022-06-01

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2022-06-13
Debian
CVE-2022-31743: firefox - Firefox's HTML parser did not correctly interpret HTML comment tags, resulting i...2022
Mozilla
Mozilla Foundation Security Advisory 2022-20: CVE-2022-31743