CVE-2022-31744
Mozilla: CSP bypass enabling stylesheet injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101.
Un atacante podría haber inyectado CSS en hojas de estilo accesibles a través de URI internos, como recurso:, y al hacerlo eludir la Política de seguridad de contenido de una página. Esta vulnerabilidad afecta a Firefox ESR < 91.11, Thunderbird < 102, Thunderbird< 91.11 y Firefox < 101.
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of an attacker that can inject CSS into stylesheets accessible via internal URIs, such as resources. In doing so, they can bypass a page's Content Security Policy.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-26 CVE Reserved
- 2022-06-19 CVE Published
- 2024-07-14 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2022-20 | 2023-08-08 | |
https://www.mozilla.org/security/advisories/mfsa2022-25 | 2023-08-08 | |
https://www.mozilla.org/security/advisories/mfsa2022-26 | 2023-08-08 | |
https://access.redhat.com/security/cve/CVE-2022-31744 | 2022-07-01 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2102165 | 2022-07-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 101.0 Search vendor "Mozilla" for product "Firefox" and version " < 101.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 91.11 Search vendor "Mozilla" for product "Firefox Esr" and version " < 91.11" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 91.11 Search vendor "Mozilla" for product "Thunderbird" and version " < 91.11" | - |
Affected
|