When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.
History

Tue, 15 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2025-04-15T18:48:58.793Z

Reserved: 2022-06-24T00:00:00.000Z

Link: CVE-2022-34471

cve-icon Vulnrichment

Updated: 2024-08-03T09:15:15.262Z

cve-icon NVD

Status : Modified

Published: 2022-12-22T20:15:31.500

Modified: 2025-04-15T19:16:03.420

Link: CVE-2022-34471

cve-icon Redhat

No data.