CVE-2022-38472Origin Validation Error in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.2%
top 61.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22

Description

An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified104
NVDmozilla/firefox102.0102.2+1
CVEListV5mozilla/firefox_esrunspecified91.13+1
CVEListV5mozilla/thunderbirdunspecified102.2+1
NVDmozilla/thunderbird102.0102.2+1

🔴Vulnerability Details

4
OSV
CVE-2022-38472: An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar2022-12-22
GHSA
GHSA-rr53-g8m7-wrvf: An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar2022-12-22
CVEList
CVE-2022-38472: An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar2022-12-22
OSV
thunderbird vulnerabilities2022-10-07

📋Vendor Advisories

9
Ubuntu
Thunderbird vulnerabilities2022-10-07
Ubuntu
Firefox vulnerabilities2022-08-24
Red Hat
Mozilla: Address bar spoofing via XSLT error handling2022-08-23
Debian
CVE-2022-38472: firefox - An attacker could have abused XSLT error handling to associate attacker-controll...2022
Mozilla
Mozilla Foundation Security Advisory 2022-36: CVE-2022-38472
CVE-2022-38472 — Origin Validation Error in Mozilla | cvebase