Related Vulnerabilities: CVE-2022-1802  

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context.

AVG-2729 thunderbird 91.9.0-1 91.9.1-1 Critical Fixed

AVG-2728 firefox 100.0.1-1 100.0.2-1 Critical Fixed

https://bugzilla.mozilla.org/show_bug.cgi?id=1770137