AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-34471

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-12-22 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Firefox.

CVE
CVE-2022-34471
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%
Firefox

Original NVD Description

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

Related CVEs

Other vulnerabilities affecting the same vendor(s)