CVE-2022-1802

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
References
Link Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=1770137 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-19/ Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1770137 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-19/ Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1770137 Issue Tracking Permissions Required Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

History

16 Apr 2025, 16:15

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1770137 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1770137 - Issue Tracking, Permissions Required, Vendor Advisory

21 Nov 2024, 06:41

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1770137 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1770137 - Issue Tracking, Permissions Required, Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-19/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-19/ - Vendor Advisory
Summary
  • (es) Si un atacante pudo corromper los métodos de un objeto Array en JavaScript mediante la contaminación de prototipos, podría haber logrado la ejecución del código JavaScript controlado por el atacante en un contexto privilegiado. Esta vulnerabilidad afecta a Firefox ESR &lt; 91.9.1, Firefox &lt; 100.0.2, Firefox para Android &lt; 100.3.0 y Thunderbird &lt; 91.9.1.

Information

Published : 2022-12-22 20:15

Updated : 2025-04-16 16:15


NVD link : CVE-2022-1802

Mitre link : CVE-2022-1802

CVE.ORG link : CVE-2022-1802


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
  • firefox_esr

google

  • android
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')