Security Advisory

CVE-2022-1802

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-12-22 00:00:00
Last updated 2025-04-16 15:17:14
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.