
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-45403 is a high-impact security vulnerability discovered in Firefox and Firefox ESR browsers that was disclosed on November 15, 2022. The vulnerability affects the Service Workers implementation, where timing information for cross-origin media combined with Range requests could potentially allow Service Workers to determine the presence or length of opaque cross-origin media files, which should not be possible (Mozilla Advisory).
The vulnerability stems from a security flaw where Service Workers could infer information about opaque cross-origin responses through timing information. The issue specifically involves the combination of cross-origin media requests and Range headers, which could be exploited to determine details about media files that should remain private. The vulnerability was rated as having a high impact by Mozilla security researchers (Mozilla Advisory).
The vulnerability could allow malicious actors to gather information about cross-origin media files that should be protected by the browser's same-origin policy. This could potentially lead to privacy breaches where Service Workers could determine the presence or length of media files hosted on different origins, compromising the confidentiality of cross-origin resources (Mozilla Advisory).
The vulnerability was fixed in Firefox 107 and Firefox ESR 102.5. The fix prevents Service Workers from intercepting cross-origin no-cors media requests, effectively blocking the timing attack vector. Users are advised to upgrade to these versions or later to protect against this vulnerability (Mozilla Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."