Show plain JSON{"acknowledgement": "Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Dongsung Kim as the original reporter.", "affected_release": [{"advisory": "RHSA-2022:8552", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "firefox-0:102.5.0-1.el7_9", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8555", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "thunderbird-0:102.5.0-2.el7_9", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8547", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "thunderbird-0:102.5.0-2.el8_7", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8554", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "firefox-0:102.5.0-1.el8_7", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8553", "cpe": "cpe:/a:redhat:rhel_e4s:8.1", "package": "firefox-0:102.5.0-1.el8_1", "product_name": "Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8556", "cpe": "cpe:/a:redhat:rhel_e4s:8.1", "package": "thunderbird-0:102.5.0-2.el8_1", "product_name": "Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8543", "cpe": "cpe:/a:redhat:rhel_aus:8.2", "package": "thunderbird-0:102.5.0-2.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8550", "cpe": "cpe:/a:redhat:rhel_aus:8.2", "package": "firefox-0:102.5.0-1.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8543", "cpe": "cpe:/a:redhat:rhel_tus:8.2", "package": "thunderbird-0:102.5.0-2.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Telecommunications Update Service", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8550", "cpe": "cpe:/a:redhat:rhel_tus:8.2", "package": "firefox-0:102.5.0-1.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Telecommunications Update Service", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8543", "cpe": "cpe:/a:redhat:rhel_e4s:8.2", "package": "thunderbird-0:102.5.0-2.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8550", "cpe": "cpe:/a:redhat:rhel_e4s:8.2", "package": "firefox-0:102.5.0-1.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8544", "cpe": "cpe:/a:redhat:rhel_eus:8.4", "package": "thunderbird-0:102.5.0-2.el8_4", "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8549", "cpe": "cpe:/a:redhat:rhel_eus:8.4", "package": "firefox-0:102.5.0-1.el8_4", "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8545", "cpe": "cpe:/a:redhat:rhel_eus:8.6", "package": "thunderbird-0:102.5.0-2.el8_6", "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8548", "cpe": "cpe:/a:redhat:rhel_eus:8.6", "package": "firefox-0:102.5.0-1.el8_6", "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8561", "cpe": "cpe:/a:redhat:enterprise_linux:9", "package": "thunderbird-0:102.5.0-2.el9_1", "product_name": "Red Hat Enterprise Linux 9", "release_date": "2022-11-21T00:00:00Z"}, {"advisory": "RHSA-2022:8580", "cpe": "cpe:/a:redhat:enterprise_linux:9", "package": "firefox-0:102.5.0-1.el9_1", "product_name": "Red Hat Enterprise Linux 9", "release_date": "2022-11-22T00:00:00Z"}, {"advisory": "RHSA-2022:8979", "cpe": "cpe:/a:redhat:rhel_eus:9.0", "package": "firefox-0:102.5.0-1.el9_0", "product_name": "Red Hat Enterprise Linux 9.0 Extended Update Support", "release_date": "2022-12-13T00:00:00Z"}, {"advisory": "RHSA-2022:8980", "cpe": "cpe:/a:redhat:rhel_eus:9.0", "package": "thunderbird-0:102.5.0-2.el9_0", "product_name": "Red Hat Enterprise Linux 9.0 Extended Update Support", "release_date": "2022-12-13T00:00:00Z"}], "bugzilla": {"description": "Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy", "id": "2143203", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2143203"}, "csaw": false, "cvss3": {"cvss3_base_score": "6.1", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "status": "verified"}, "cwe": "CWE-1275", "details": ["When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.", "The Mozilla Foundation Security Advisory describes this flaw as: When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers."], "name": "CVE-2022-45410", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Out of support scope", "package_name": "firefox", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Out of support scope", "package_name": "thunderbird", "product_name": "Red Hat Enterprise Linux 6"}], "public_date": "2022-11-15T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2022-45410\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-45410\nhttps://www.mozilla.org/en-US/security/advisories/mfsa2022-48/#CVE-2022-45410\nhttps://www.mozilla.org/en-US/security/advisories/mfsa2022-49/#CVE-2022-45410"], "threat_severity": "Moderate"}