Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2022-36318
HistoryDec 22, 2022 - 8:15 p.m.

CVE-2022-36318

2022-12-2220:15:35
Debian Security Bug Tracker
security-tracker.debian.org
21
cve-2022-36318
firefox esr
firefox
thunderbird
url reflection
directory listings
unix

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

55.1%

When visiting directory listings for chrome:// URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

55.1%