6.5
CVSSv3

CVE-2022-45419

Published: 22/12/2022 Updated: 04/01/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted. This vulnerability affects Firefox < 107.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Several security issues were fixed in Firefox ...
Mozilla Foundation Security Advisory 2022-47 Security Vulnerabilities fixed in Firefox 107 Announced November 15, 2022 Impact high Products Firefox Fixed in Firefox 107 ...