CVE-2022-45420UI Misrepresentation / Clickjacking in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV8.1
EPSS
0.1%
top 66.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateFeb 6

Description

Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified107
NVDmozilla/firefox< 107.0
CVEListV5mozilla/firefox_esrunspecified102.5
NVDmozilla/firefox_esr< 102.5
Ubuntumozilla/firefox< 107.0+build2-0ubuntu0.18.04.1+1

🔴Vulnerability Details

5
OSV
thunderbird vulnerabilities2023-02-06
CVEList
CVE-2022-45420: Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potent2022-12-22
GHSA
GHSA-6pf3-q3cx-w87c: Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potent2022-12-22
OSV
CVE-2022-45420: Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potent2022-12-22
OSV
firefox vulnerabilities2022-11-16

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-02-06
Ubuntu
Firefox vulnerabilities2022-11-16
Red Hat
Mozilla: Iframe contents could be rendered outside the iframe2022-11-15
Debian
CVE-2022-45420: firefox - Use tables inside of an iframe, an attacker could have caused iframe contents to...2022
Mozilla
Mozilla Foundation Security Advisory 2022-47: CVE-2022-45420
CVE-2022-45420 — UI Misrepresentation / Clickjacking | cvebase