CVE-2022-29916

MEDIUM

Firefox < 100.0 and Firefox ESR < 91.9 - Browser History Probing via CSS Variable Resource Loading

Title source: llm
STIX 2.1

Description

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

References (4)

Core 4

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 47.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
mozilla/firefox < 100.0
mozilla/firefox_esr < 91.9
mozilla/thunderbird < 91.9
Published Dec 22, 2022
Tracked Since Feb 18, 2026