CVE-2022-34469
Published on: Not Yet Published
Last Modified on: 01/04/2023 04:41:00 PM UTC
Certain versions of Android from Google contain the following vulnerability:
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.
- CVE-2022-34469 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Mozilla - Firefox version < 102
CVSS3 Score: 8.1 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Vulnerabilities fixed in Firefox 102 — Mozilla | www.mozilla.org text/html |
![]() |
Access Denied | bugzilla.mozilla.org text/html |
![]() |
Related QID Numbers
- 376705 Mozilla Firefox Multiple Vulnerabilities (MFSA2022-24)
- 630846 Firefox For Android Improper Certificate Validation Vulnerability
- 710582 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202208-08)
- 752583 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3273-1)
- 752590 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3272-1)
- 752611 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3396-1)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Android | - | All | All | All | |
Application | Mozilla | Firefox | All | All | All | All |
- cpe:2.3:o:google:android:-:*:*:*:*:*:*:*:
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution - PATCH: NOW | 2022-06-30 13:31:17 |