CVE Database
/

CVE-2022-45419

Back to search

CVE-2022-45419

Published: Dec 22, 2022

Modified: Apr 15, 2025

PUBLISHED

Description

If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted. This vulnerability affects Firefox < 107.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 107

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now