When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Oct 20, 2022 | Sep 26, 2022 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Dec 7, 2022 | Dec 7, 2022 |
| Centos_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird | Oct 20, 2022 | Sep 26, 2022 |
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Dec 22, 2022 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 91.13.1 | Sep 1, 2022 | Aug 31, 2022 |
| Oracle_linux | — | Upgrade thunderbird | Sep 29, 2022 | Aug 31, 2022 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoNo solution exists | Oct 20, 2022 | Sep 26, 2022 |
| Rocky_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade thunderbird-debuginfo | Mar 12, 2024 | Dec 22, 2022 |
| Suse | — | Upgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-common | Oct 26, 2022 | Sep 15, 2022 |
| Ubuntu | — | Upgrade thunderbird | Oct 8, 2022 | Sep 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub