CVE-2022-45411
Mozilla: Cross-Site Tracing was possible via non-standard override headers
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on <code>fetch()</code> and XMLHttpRequest; however some webservers have implemented non-standard headers such as <code>X-Http-Method-Override</code> that override the HTTP method, and made this attack possible again. Thunderbird has applied the same mitigations to the use of this and similar headers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
El seguimiento entre sitios se produce cuando un servidor repite una solicitud a través del método Trace, lo que permite que un ataque XSS acceda a encabezados de autorización y cookies inaccesibles para JavaScript (como las cookies protegidas por HTTPOnly). Para mitigar este ataque, los navegadores impusieron límites a <code>fetch()</code> y XMLHttpRequest; sin embargo, algunos servidores web han implementado encabezados no estándar como <code>X-Http-Method-Override</code> que anulan el método HTTP e hicieron posible este ataque nuevamente. Thunderbird ha aplicado las mismas mitigaciones al uso de este y encabezados similares. Esta vulnerabilidad afecta a Firefox ESR < 102,5, Thunderbird < 102.5 y Firefox < 107.
The Mozilla Foundation Security Advisory describes this flaw as: Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on fetch() and XMLHttpRequest; however some webservers have implemented non-standard headers such as X-Http-Method-Override that override the HTTP method, and made this attack possible again. Firefox has applied the same mitigations to the use of this and similar headers.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-14 CVE Reserved
- 2022-11-16 CVE Published
- 2024-07-14 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2022-47 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-48 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-49 | 2023-01-04 | |
https://access.redhat.com/security/cve/CVE-2022-45411 | 2022-12-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2143204 | 2022-12-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 107.0 Search vendor "Mozilla" for product "Firefox" and version " < 107.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 102.5 Search vendor "Mozilla" for product "Firefox Esr" and version " < 102.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 102.5 Search vendor "Mozilla" for product "Thunderbird" and version " < 102.5" | - |
Affected
|