When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-345 | |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-04-15T18:48:58.793Z
Reserved: 2022-06-24T00:00:00.000Z
Link: CVE-2022-34471

Updated: 2024-08-03T09:15:15.262Z

Status : Modified
Published: 2022-12-22T20:15:31.500
Modified: 2025-04-15T19:16:03.420
Link: CVE-2022-34471

No data.