CVE-2022-34477

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/12/2022
Last modified:
15/04/2025

Description

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 102.0 (excluding)