CVE-2022-45411

Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on <code>fetch()</code> and XMLHttpRequest; however some webservers have implemented non-standard headers such as <code>X-Http-Method-Override</code> that override the HTTP method, and made this attack possible again. Thunderbird has applied the same mitigations to the use of this and similar headers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

15 Apr 2025, 15:16

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1790311 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1790311 - Issue Tracking, Permissions Required, Vendor Advisory

21 Nov 2024, 07:29

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1790311 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1790311 - Issue Tracking, Permissions Required, Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-47/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-47/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-48/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-48/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-49/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-49/ - Vendor Advisory
Summary
  • (es) El seguimiento entre sitios se produce cuando un servidor repite una solicitud a través del método Trace, lo que permite que un ataque XSS acceda a encabezados de autorización y cookies inaccesibles para JavaScript (como las cookies protegidas por HTTPOnly). Para mitigar este ataque, los navegadores impusieron límites a <code>fetch()</code> y XMLHttpRequest; sin embargo, algunos servidores web han implementado encabezados no estándar como <code>X-Http-Method-Override</code> que anulan el método HTTP e hicieron posible este ataque nuevamente. Thunderbird ha aplicado las mismas mitigaciones al uso de este y encabezados similares. Esta vulnerabilidad afecta a Firefox ESR &lt; 102,5, Thunderbird &lt; 102.5 y Firefox &lt; 107.

Information

Published : 2022-12-22 20:15

Updated : 2025-04-15 15:16


NVD link : CVE-2022-45411

Mitre link : CVE-2022-45411

CVE.ORG link : CVE-2022-45411


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
  • firefox_esr
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')