cve/2022/CVE-2022-29909.md
2024-06-18 02:51:15 +02:00

1.1 KiB

CVE-2022-29909

Description

Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

POC

Reference

Github

No PoCs found on GitHub currently.