MFSA2022-05 Firefox: Security Vulnerabilities fixed in Firefox ESR 91.6 (CVE-2022-22759)
Description
If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox.
Solution(s)
mozilla-firefox-esr-upgrade-91_6
Referenceshttps://attackerkb.com/topics/cve-2022-22759CVE - 2022-22759http://www.mozilla.org/security/announce/2022/mfsa2022-05.html