CVE-2022-26382 - log back

CVE-2022-26382 edited at 14 May 2022 21:08:40
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
Description
+ While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage.
References
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1741888
Notes
CVE-2022-26382 created at 14 May 2022 21:05:23