CVE-2022-22761 describes a vulnerability in Firefox, Thunderbird, and Firefox ESR where web-accessible extension pages failed to properly enforce the frame-ancestors Content Security Policy directive. This high-severity vulnerability (CVSS 8.8) could allow an attacker to embed extension pages within malicious frames, potentially leading to high impact on confidentiality, integrity, and availability. While the vulnerability is significant, there is currently no evidence of active exploitation, publicly available exploit code, or notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 97.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 91.6CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 91.6CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.