CVE-2022-46873

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
22/12/2022
Last modified:
15/04/2025

Description

Because Firefox did not implement the unsafe-hashes CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 108.0 (excluding)