cbcvebase.
CVE-2022-34469
published 2022-12-22

CVE-2022-34469: When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox…

PriorityP337high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
0.37%
29.3th percentile
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianfirefox
mozillafirefox< 102.0102.0
mozillafirefox
mozillafirefox>= unspecified < 102102

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
vendor_debian8.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.