Closed Bug 1766047 (CVE-2022-34471) Opened 2 years ago Closed 2 years ago

Verify that version of downloaded XPI matches with the version from the update manifest

Categories

(WebExtensions :: General, defect, P2)

defect
Points:
2

Tracking

(firefox-esr91 wontfix, firefox100 wontfix, firefox101 wontfix, firefox102+ fixed)

RESOLVED FIXED
102 Branch
Tracking Status
firefox-esr91 --- wontfix
firefox100 --- wontfix
firefox101 --- wontfix
firefox102 + fixed

People

(Reporter: robwu, Assigned: robwu)

References

Details

(Keywords: sec-moderate, Whiteboard: [addons-jira][post-critsmash-triage][adv-main102+])

Attachments

(2 files)

We have logic that only select new versions from the update manifest. But after downloading we don't confirm whether the downloaded version matches the expected version. To avoid unintended downgrades when the update manifest has been tampered with on the server's end, we should prevent this from happening.

Depends on: 1766087
Severity: -- → N/A
Type: task → defect
Priority: -- → P2
Severity: N/A → S2
Group: firefox-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED
Target Milestone: --- → 102 Branch
Flags: qe-verify+
Whiteboard: [addons-jira] → [addons-jira][post-critsmash-triage]

Covered by unit tests.

Flags: qe-verify+ → qe-verify-
Whiteboard: [addons-jira][post-critsmash-triage] → [addons-jira][post-critsmash-triage][adv-main102+]
Alias: CVE-2022-34471
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: