The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include local files or other files that should have been inaccessible. This vulnerability affects Firefox < 99.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2022-13/ | vendor advisory exploit |
https://bugzilla.mozilla.org/show_bug.cgi?id=1754066 | vendor advisory issue tracking exploit |