CVE-2022-45417

Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk for websites visited in Private Browsing Mode. This would not have persisted them in a state where they would run again, but it would have leaked Private Browsing Mode details to disk. This vulnerability affects Firefox < 107.
References
Link Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=1794508 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-47/ Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

04 Jan 2023, 19:42

Type Values Removed Values Added
First Time Mozilla firefox
Mozilla
CWE CWE-1021
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
References (MISC) https://www.mozilla.org/security/advisories/mfsa2022-47/ - (MISC) https://www.mozilla.org/security/advisories/mfsa2022-47/ - Vendor Advisory
References (MISC) https://bugzilla.mozilla.org/show_bug.cgi?id=1794508 - (MISC) https://bugzilla.mozilla.org/show_bug.cgi?id=1794508 - Issue Tracking, Permissions Required, Vendor Advisory

22 Dec 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-22 20:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-45417

Mitre link : CVE-2022-45417

CVE.ORG link : CVE-2022-45417


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames