{"api_version":"1","generated_at":"2026-04-23T08:14:57+00:00","cve":"CVE-2022-34469","urls":{"html":"https://cve.report/CVE-2022-34469","api":"https://cve.report/api/cve/CVE-2022-34469.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-34469","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-34469"},"summary":{"title":"CVE-2022-34469","description":"When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.","state":"PUBLIC","assigner":"security@mozilla.org","published_at":"2022-12-22 20:15:00","updated_at":"2023-01-04 16:41:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://www.mozilla.org/security/advisories/mfsa2022-24/","name":"https://www.mozilla.org/security/advisories/mfsa2022-24/","refsource":"MISC","tags":[],"title":"Security Vulnerabilities fixed in Firefox 102 — Mozilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1721220","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1721220","refsource":"MISC","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-34469","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-34469","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"34469","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"34469","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-34469","qid":"376705","title":"Mozilla Firefox Multiple Vulnerabilities (MFSA2022-24)"},{"cve":"CVE-2022-34469","qid":"502853","title":"Alpine Linux Security Update for firefox"},{"cve":"CVE-2022-34469","qid":"505737","title":"Alpine Linux Security Update for firefox"},{"cve":"CVE-2022-34469","qid":"630846","title":"Firefox For Android Improper Certificate Validation Vulnerability"},{"cve":"CVE-2022-34469","qid":"710582","title":"Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202208-08)"},{"cve":"CVE-2022-34469","qid":"752583","title":"SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3273-1)"},{"cve":"CVE-2022-34469","qid":"752590","title":"SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3272-1)"},{"cve":"CVE-2022-34469","qid":"752611","title":"SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3396-1)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2022-34469","ASSIGNER":"security@mozilla.org","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Mozilla","product":{"product_data":[{"product_name":"Firefox","version":{"version_data":[{"version_value":"102","version_affected":"<"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"TLS certificate errors on HSTS-protected domains could be bypassed by the user on Firefox for Android"}]}]},"references":{"reference_data":[{"url":"https://www.mozilla.org/security/advisories/mfsa2022-24/","refsource":"MISC","name":"https://www.mozilla.org/security/advisories/mfsa2022-24/"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1721220","refsource":"MISC","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1721220"}]},"description":{"description_data":[{"lang":"eng","value":"When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102."}]}},"nvd":{"publishedDate":"2022-12-22 20:15:00","lastModifiedDate":"2023-01-04 16:41:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndExcluding":"102.0","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":null,"notes":[]}}}