Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2022-36315
HistoryDec 22, 2022 - 8:15 p.m.

CVE-2022-36315

2022-12-2220:15:35
Alpine Linux Development Team
security.alpinelinux.org
19
script injection attack
cache reuse
integrity metadata
cve-2022-36315
unix

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

6.2 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

32.4%

When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

6.2 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

32.4%