CVE-2022-22744 Information
Description
The constructed curl command from the \Copy as curl\ feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.
This bug only affects Thunderbird for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 91.5 Firefox < 96 and Thunderbird < 91.5.
Reference
https://www.mozilla.org/security/advisories/mfsa2022-02/
https://www.mozilla.org/security/advisories/mfsa2022-01/
https://www.mozilla.org/security/advisories/mfsa2022-03/
https://bugzilla.mozilla.org/show_bug.cgi?id=1737252
The
constructed
curl
command
from
the
\Copy
as
curl
feature
in
DevTools
was
not
properly
escaped
for
PowerShell.
This
could
have
lead
to
command
injection
if
pasted
into
a
Powershell
prompt.
This
bug
only
affects
Thunderbird
for
Windows.
Other
operating
systems
are
unaffected..
This
vulnerability
affects
Firefox
ESR
<
91.5
Firefox
<
96
and
Thunderbird
<
91.5.