When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Oct 20, 2022 | Sep 26, 2022 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Dec 7, 2022 | Dec 7, 2022 |
| Centos_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | Oct 20, 2022 | Sep 26, 2022 |
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Dec 22, 2022 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 91.13.1 | Sep 1, 2022 | Aug 31, 2022 |
| Oracle_linux | — | Upgrade thunderbird | Sep 29, 2022 | Aug 31, 2022 |
| Redhat_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbirdNo solution existsUpgrade thunderbird-debuginfo | Oct 20, 2022 | Sep 26, 2022 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsource | Mar 12, 2024 | Dec 22, 2022 |
| Suse | — | Upgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird-translations-common | Oct 26, 2022 | Sep 15, 2022 |
| Ubuntu | — | Upgrade thunderbird | Oct 8, 2022 | Sep 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub