CVE-2022-45410Missing Authorization in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV8.1
EPSS
0.2%
top 64.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateOct 15

Description

When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified107
NVDmozilla/firefox< 107.0
CVEListV5mozilla/firefox_esrunspecified102.5
NVDmozilla/firefox_esr< 102.5
Ubuntumozilla/firefox< 107.0+build2-0ubuntu0.18.04.1+1

🔴Vulnerability Details

5
OSV
thunderbird vulnerabilities2023-02-06
GHSA
GHSA-gvhf-4hjq-39hg: When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it2022-12-22
OSV
CVE-2022-45410: When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it2022-12-22
CVEList
CVE-2022-45410: When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it2022-12-22
OSV
firefox vulnerabilities2022-11-16

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2023-02-06
Microsoft
When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cooki2022-12-13
Ubuntu
Firefox vulnerabilities2022-11-16
Red Hat
Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy2022-11-15
Debian
CVE-2022-45410: firefox - When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the ori...2022

💬Community

1
HackerOne
SameSite restrictions are lifted, and SameSite:Strict cookie are being sent.2025-10-15
CVE-2022-45410 — Missing Authorization in Mozilla | cvebase