When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
History

Tue, 15 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2025-04-15T14:37:47.758Z

Reserved: 2022-11-14T00:00:00.000Z

Link: CVE-2022-45410

cve-icon Vulnrichment

Updated: 2024-08-03T14:09:57.033Z

cve-icon NVD

Status : Modified

Published: 2022-12-22T20:15:43.067

Modified: 2025-04-15T15:16:01.480

Link: CVE-2022-45410

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-11-15T00:00:00Z

Links: CVE-2022-45410 - Bugzilla