CVE-2022-36315Insufficient Verification of Data Authenticity in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 63.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22

Description

When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages6 packages

debiandebian/firefox< firefox 103.0-1 (sid)
CVEListV5mozilla/firefoxunspecified103
NVDmozilla/firefox< 103.0
Ubuntumozilla/firefox< 103.0+build1-0ubuntu0.18.04.1+1
mozillamozilla/firefox

🔴Vulnerability Details

2
GHSA
GHSA-vf28-r8mx-j24p: When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with inc2022-12-22
OSV
CVE-2022-36315: When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with inc2022-07-27

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2022-07-28
Debian
CVE-2022-36315: firefox - When loading a script with Subresource Integrity, attackers with an injection ca...2022
Mozilla
Mozilla Foundation Security Advisory 2022-28: CVE-2022-36315