When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2022-12-22T00:00:00

Updated: 2024-08-03T14:09:57.033Z

Reserved: 2022-11-14T00:00:00

Link: CVE-2022-45410

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-12-22T20:15:43.067

Modified: 2023-01-04T17:43:48.467

Link: CVE-2022-45410

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-11-15T00:00:00Z

Links: CVE-2022-45410 - Bugzilla