CVE-2022-42930Race Condition in Mozilla Firefox

CWE-362Race Condition9 documents6 sources
Severity
7.1HIGHNVD
OSV8.1
EPSS
0.3%
top 49.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22

Description

If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages6 packages

debiandebian/firefox< firefox 106.0-1 (sid)
CVEListV5mozilla/firefoxunspecified106
NVDmozilla/firefox< 106.0
Ubuntumozilla/firefox< 106.0.2+build1-0ubuntu0.18.04.1+3
mozillamozilla/firefox

🔴Vulnerability Details

4
GHSA
GHSA-737f-pfm5-cmq6: If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the ThirdPartyUtil component2022-12-22
OSV
firefox vulnerabilities2022-11-10
OSV
firefox vulnerabilities2022-11-01
OSV
CVE-2022-42930: If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component2022-10-27

📋Vendor Advisories

4
Ubuntu
Firefox vulnerabilities2022-11-10
Ubuntu
Firefox vulnerabilities2022-11-01
Debian
CVE-2022-42930: firefox - If two Workers were simultaneously initializing their CacheStorage, a data race ...2022
Mozilla
Mozilla Foundation Security Advisory 2022-44: CVE-2022-42930