CVE-2022-46873: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.
Affected products
- Mozilla Firefox: before 108.0 (fixed in 108.0)
Published 2022-12-22. Last modified 2026-06-17.