CVE-2022-45411

CVSS v3.1 6.1 (Medium)
61% Progress
EPSS 0.09 % (40th)
0.09% Progress
Affected Products 3
Advisories 34

Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on <code>fetch()</code> and XMLHttpRequest; however some webservers have implemented non-standard headers such as <code>X-Http-Method-Override</code> that override the HTTP method, and made this attack possible again. Thunderbird has applied the same mitigations to the use of this and similar headers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2022-12-22 20:15:43
(21 months ago)
Updated Date
2023-01-04 14:34:23
(20 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 107.0 version cpe:2.3:a:mozilla:firefox < 107.0
  Mozilla Firefox Esr prior 102.5 version cpe:2.3:a:mozilla:firefox_esr < 102.5
  Mozilla Thunderbird prior 102.5 version cpe:2.3:a:mozilla:thunderbird < 102.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...