Lucene search

K
nvd[email protected]NVD:CVE-2022-36318
HistoryDec 22, 2022 - 8:15 p.m.

CVE-2022-36318

2022-12-2220:15:35
CWE-362
web.nvd.nist.gov
cve-2022-36318
directory listings
chrome urls
reflected parameters
firefox esr
firefox
thunderbird

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

55.1%

When visiting directory listings for chrome:// URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

Affected configurations

NVD
Node
mozillafirefoxRange<103.0
OR
mozillafirefox_esrRange<102.1
OR
mozillathunderbirdRange<102.1
Node
mozillafirefox_esrRange<91.12
OR
mozillathunderbirdRange<91.12

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

55.1%