CVE-2022-34471
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-34471 is a moderate severity vulnerability discovered in Firefox that affects the browser's addon update mechanism. The vulnerability was reported by Rob Wu and fixed in Firefox 102, released on June 28, 2022. The issue affects Mozilla Firefox's addon update verification process (Mozilla Advisory).

Technical details

The vulnerability stems from a verification flaw where the downloaded addon update's version was not properly verified against the version selected from the manifest. When downloading an update for an addon, the browser failed to verify that the downloaded addon update's version matched the version selected from the manifest (Mozilla Advisory, Mozilla Bug).

Impact

If the manifest had been tampered with on the server, an attacker could exploit this vulnerability to trick the browser into downgrading an addon to a prior version. This could potentially expose users to security vulnerabilities that were present in older versions of the addon (Mozilla Advisory).

Mitigation and workarounds

The vulnerability was fixed in Firefox 102. Users should update to Firefox version 102 or later to receive the security fix. The fix includes implementing verification checks to ensure that the downloaded addon version matches the version selected from the manifest (Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • rhel10::firefox-flatpak
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • rhel10::thunderbird-flatpak
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management