CVE-2022-45413Open Redirect in Mozilla Firefox

CWE-601Open Redirect8 documents7 sources
Severity
6.1MEDIUMNVD
OSV8.1
EPSS
0.2%
top 61.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateOct 15

Description

Using the S.browser_fallback_url parameter parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

CVEListV5mozilla/firefoxunspecified107
NVDmozilla/firefox< 107.0
Ubuntumozilla/firefox< 107.0+build2-0ubuntu0.18.04.1+1
mozillamozilla/firefox

🔴Vulnerability Details

3
GHSA
GHSA-h295-679q-mhm8: Using the S2022-12-22
OSV
CVE-2022-45413: Using the S2022-11-16
OSV
firefox vulnerabilities2022-11-16

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2022-11-16
Debian
CVE-2022-45413: firefox - Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker c...2022
Mozilla
Mozilla Foundation Security Advisory 2022-47: CVE-2022-45413

💬Community

1
HackerOne
SameSite restrictions are lifted, and SameSite:Strict cookie are being sent.2025-10-15