CVE-2022-34468
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-34468 is a high-impact security vulnerability discovered in Firefox and Firefox ESR browsers that affects Content Security Policy (CSP) sandbox implementation. The vulnerability was discovered by Armin Ebert and disclosed on June 28, 2022. The issue affects Firefox versions prior to 102 and Firefox ESR versions prior to 91.11 (Mozilla Advisory).

Technical details

The vulnerability allows an iframe that was not permitted to run scripts to bypass the CSP sandbox header restriction when a user clicks on a javascript: link. Specifically, when a CSP sandbox header is set without the 'allow-scripts' directive, the sandbox flags were incorrectly taken from the browsing context instead of the document, allowing script execution that should have been blocked (Mozilla Advisory, Mozilla Bug).

Impact

The vulnerability has been rated as having a high impact. It allows malicious websites to bypass security restrictions and execute JavaScript code in contexts where script execution should be forbidden by the Content Security Policy sandbox. This could potentially lead to unauthorized script execution and compromise of the affected browser's security model (Mozilla Advisory).

Mitigation and workarounds

The vulnerability was fixed in Firefox 102 and Firefox ESR 91.11. The fix involves correcting the code to properly check the sandbox flags from the document instead of the browsing context. Users are advised to upgrade to these or later versions to protect against this vulnerability (Mozilla Advisory, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12819HIGH8.1
  • NixOSNixOS
  • pgbouncer
NoYesDec 03, 2025
CVE-2025-20777MEDIUM6.7
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-65105MEDIUM5.3
  • NixOSNixOS
  • apptainer
NoYesDec 02, 2025
CVE-2025-20789MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-20788MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management