
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-28282 is a use-after-free vulnerability discovered in Mozilla products that affects Firefox < 99, Firefox ESR < 91.8, and Thunderbird < 91.8. The vulnerability was discovered by security researcher Kirin and disclosed on April 5, 2022. The issue occurs in the DocumentL10n::TranslateDocument functionality when using a link with rel="localization" attribute (Mozilla Advisory, CVE Details).
The vulnerability is triggered when using a link element with rel="localization" attribute, which can cause a use-after-free condition by destroying an object during JavaScript execution and then referencing the object through a freed pointer. The issue occurs specifically in the DocumentL10n::TranslateDocument functionality. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium), with attack vector: Network, attack complexity: Low, privileges required: None, user interaction: Required, scope: Unchanged, and impact primarily affecting availability (Ubuntu Security).
The exploitation of this vulnerability could lead to a potentially exploitable crash of the affected application. While the direct impact appears to be a denial of service condition, the use-after-free condition could potentially be leveraged for arbitrary code execution under certain circumstances (Mozilla Advisory, Mozilla Bug).
The vulnerability requires user interaction and can be triggered through privileged contexts such as browser extensions. While it cannot be exploited directly through email in Thunderbird (as scripting is disabled when reading mail), it remains a potential risk in browser or browser-like contexts. The vulnerability was confirmed to be exploitable through a proof-of-concept demonstrated using a Firefox extension (Mozilla Bug).
The vulnerability has been fixed in Firefox 99, Firefox ESR 91.8, and Thunderbird 91.8. The fix involves properly managing the reference counting of DocumentL10n objects to prevent the use-after-free condition. Users are advised to upgrade to these versions or later to mitigate the vulnerability (Mozilla Advisory, Mozilla Advisory ESR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."