CVE-2022-34469
published 2022-12-22CVE-2022-34469: When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox…
PriorityP337high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
0.37%
29.3th percentile
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 102.0 | 102.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 102 | 102 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
vendor_debian8.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-454w-5cf7-2xqx: When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error
ghsa_unreviewed·2022-12-22
CVE-2022-34469 [HIGH] CWE-295 GHSA-454w-5cf7-2xqx: When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.
Debian
CVE-2022-34469: firefox - When a TLS Certificate error occurs on a domain protected by the HSTS header, th...
vendor_debian·2022·CVSS 8.1
CVE-2022-34469 [HIGH] CVE-2022-34469: firefox - When a TLS Certificate error occurs on a domain protected by the HSTS header, th...
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2022-24: CVE-2022-34469
vendor_mozilla·CVSS 8.1
CVE-2022-34469 [HIGH] Mozilla Foundation Security Advisory 2022-24: CVE-2022-34469
Mozilla Foundation Security Advisory 2022-24
CVE: CVE-2022-34469
Product: Firefox
Impact: moderate
Fixed in: Firefox 102
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-22
Published