CVE-2022-28284
high
CVSS v3
—
CVSS v2
—
VIR risk
8.0
Description
SVG's <code><use></code> element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs. This vulnerability affects Firefox < 99.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-28284
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2022-28284.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 99.0-1 | |
| debian | sid | fixed | 99.0-1 |
| sles | affected | |
References
Verify integrity in audit chain (admin only). AS-IS.