CVE-2022-29916

medium

Description

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

References

https://bugzilla.mozilla.org/show_bug.cgi?id=1760674

https://www.mozilla.org/security/advisories/mfsa2022-17/

https://www.mozilla.org/security/advisories/mfsa2022-16/

https://www.mozilla.org/security/advisories/mfsa2022-18/

Details

Source: MITRE

Published: 2022-12-22

Updated: 2022-12-30