CVE-2022-46873

CVSS v3.1 8.8 (High)
88% Progress
EPSS 0.31 % (71th)
0.31% Progress
Affected Products 1
Advisories 3

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

Weaknesses
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2022-12-22 20:15:46
(21 months ago)
Updated Date
2023-05-03 11:15:12
(16 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 108.0 version cpe:2.3:a:mozilla:firefox < 108.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...