CVE Database
/

CVE-2022-46873

Back to search

CVE-2022-46873

Published: Dec 22, 2022

Modified: Apr 15, 2025

PUBLISHED

Description

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 108

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now