CVE-2022-45410
Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Cuando un ServiceWorker interceptó una solicitud con <code>FetchEvent</code>, el origen de la solicitud se perdió después de que ServiceWorker tomó posesión de ella. Esto tuvo el efecto de anular las protecciones de cookies de SameSite. Esto se solucionó en la especificación y luego en los navegadores. Esta vulnerabilidad afecta a Firefox ESR < 102,5, Thunderbird < 102.5 y Firefox < 107.
The Mozilla Foundation Security Advisory describes this flaw as: When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-14 CVE Reserved
- 2022-11-16 CVE Published
- 2024-07-14 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1275: Sensitive Cookie with Improper SameSite Attribute
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2022-47 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-48 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-49 | 2023-01-04 | |
https://access.redhat.com/security/cve/CVE-2022-45410 | 2022-12-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2143203 | 2022-12-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 107.0 Search vendor "Mozilla" for product "Firefox" and version " < 107.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 102.5 Search vendor "Mozilla" for product "Firefox Esr" and version " < 102.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 102.5 Search vendor "Mozilla" for product "Thunderbird" and version " < 102.5" | - |
Affected
|