suse · CVE-2022-1802

Quick triage

Priority: high Published: 2022-05-21 23:49:11 UTC Updated: 2026-03-05 04:56:35 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2022-1802 severity important: SUSE including 41 source package names (MozillaFirefox-100.0.2-1.1, MozillaFirefox-140.2.0-160000.1.2, …), 255 product×package rows across 83 product lines (Container suse/kiosk/firefox-esr, HPE Helion OpenStack 8, … (83 product lines)): Fixed 255.

Description:

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.

cvelogic Threat Intelligence