When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-37426 | When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102. |
Ubuntu USN |
USN-5504-1 | Firefox vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-04-15T18:48:58.793Z
Reserved: 2022-06-24T00:00:00.000Z
Link: CVE-2022-34471
Updated: 2024-08-03T09:15:15.262Z
Status : Modified
Published: 2022-12-22T20:15:31.500
Modified: 2025-04-15T19:16:03.420
Link: CVE-2022-34471
No data.
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN