CVE-2022-45411Cross-site Scripting in Mozilla Firefox

CWE-79Cross-site Scripting13 documents8 sources
Severity
6.1MEDIUMNVD
OSV8.1OSV6.5
EPSS
0.2%
top 54.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateFeb 6

Description

Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on fetch() and XMLHttpRequest; however some webservers have implemented non-standard headers such as X-Http-Method-Override that override the HTTP method, and made this attack possible again. Thunderbird has applied the same mi

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified107
NVDmozilla/firefox< 107.0
CVEListV5mozilla/firefox_esrunspecified102.5
CVEListV5mozilla/thunderbirdunspecified102.5
NVDmozilla/firefox_esr< 102.5

🔴Vulnerability Details

5
OSV
thunderbird vulnerabilities2023-02-06
GHSA
GHSA-42wf-78r8-wp79: Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and c2022-12-22
CVEList
CVE-2022-45411: Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and c2022-12-22
OSV
CVE-2022-45411: Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and c2022-12-22
OSV
firefox vulnerabilities2022-11-16

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-02-06
Ubuntu
Firefox vulnerabilities2022-11-16
Red Hat
Mozilla: Cross-Site Tracing was possible via non-standard override headers2022-11-15
Debian
CVE-2022-45411: firefox - Cross-Site Tracing occurs when a server will echo a request back via the Trace m...2022
Mozilla
Mozilla Foundation Security Advisory 2022-49: CVE-2022-45411
CVE-2022-45411 — Cross-site Scripting in Mozilla | cvebase