Related Vulnerabilities: CVE-2022-34468  

A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of an iframe that was not permitted to run scripts could do so if the user clicked on a `javascript:` link.

Description

A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of an iframe that was not permitted to run scripts could do so if the user clicked on a `javascript:` link.

Additional Information

  • Bugzilla 2102163: CVE-2022-34468 Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • FAQ: Frequently asked questions about CVE-2022-34468