Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2022-31743
HistoryDec 22, 2022 - 8:15 p.m.

CVE-2022-31743

2022-12-2220:15:29
Debian Security Bug Tracker
security-tracker.debian.org
26
firefox
html parser
vulnerability
user-controlled data
incongruity
browsers
escape

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

34.6%

Firefox’s HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.

OSVersionArchitecturePackageVersionFilename
Debian999allfirefox< 101.0-1firefox_101.0-1_all.deb

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

34.6%