CVE-2022-36318
Mozilla: Directory indexes for bundled resources reflected URL parameters
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
Al visitar listados de directorios para URL `chrome://` como texto fuente, se reflejaron algunos parĂ¡metros. Esta vulnerabilidad afecta a Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird< 102.1 y Thunderbird < 91.12.
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of when visiting directory listings for `chrome://` URLs as source text, some parameters were reflected.
An update that fixes two vulnerabilities is now available. This update for MozillaFirefox fixes the following issues. Firefox Extended Support Release 91.12.0 ESR. Mouse Position spoofing with CSS transforms Directory indexes for bundled resources reflected URL parameters.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2022-07-20 CVE Reserved
- 2022-07-28 CVE Published
- 2025-03-30 EPSS Updated
- 2025-04-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (8)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1771774 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-28 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-29 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-30 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-31 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-32 | 2023-01-04 | |
https://access.redhat.com/security/cve/CVE-2022-36318 | 2022-08-01 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2111908 | 2022-08-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 103.0 Search vendor "Mozilla" for product "Firefox" and version " < 103.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 102.1 Search vendor "Mozilla" for product "Firefox Esr" and version " < 102.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 102.1 Search vendor "Mozilla" for product "Thunderbird" and version " < 102.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 91.12 Search vendor "Mozilla" for product "Firefox Esr" and version " < 91.12" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 91.12 Search vendor "Mozilla" for product "Thunderbird" and version " < 91.12" | - |
Affected
|