CVE-2022-1802
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 26.71% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1321
- Affected
- mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1770137Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-19/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1770137Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-19/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1770137Issue Tracking, Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.