Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | May 4, 2022 | Dec 8, 2021 |
| Alpine Linux | — | Upgrade thunderbird | Aug 22, 2024 | Dec 8, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 8, 2021 |
| Centos_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird | Dec 10, 2021 | Dec 8, 2021 |
| Debian | — | Upgrade thunderbird | Jan 4, 2022 | Dec 8, 2021 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Aug 11, 2022 | Dec 8, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.4 | Dec 8, 2021 | Dec 7, 2021 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 91.4.0-11.4.41.0.1.107.2 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 91.4.0-11.4.41.0.1.107.2 on Solaris 11.4Upgrade web/browser/firefox to version 91.4.0-11.4.41.0.1.107.2 on Solaris 11.4 | Jan 19, 2022 | Dec 8, 2021 |
| Oracle_linux | — | Upgrade thunderbird | Dec 10, 2021 | Dec 7, 2021 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoNo solution existsUpgrade thunderbirdUpgrade thunderbird-debugsource | Dec 10, 2021 | Dec 8, 2021 |
| Rocky_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird | Mar 12, 2024 | Dec 8, 2021 |
| Suse | — | Upgrade mozillathunderbirdUpgrade mozillathunderbird-translations-otherUpgrade mozillathunderbird-translations-common | Dec 23, 2021 | Dec 8, 2021 |
| Ubuntu | — | Upgrade thunderbird | Jan 22, 2022 | Dec 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub