When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-thunderbird | Oct 20, 2022 | Sep 26, 2022 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-thunderbirdamazon-linux-ami-2-upgrade-thunderbird-debuginfo | Dec 7, 2022 | Dec 7, 2022 | |
| Centos_linux | — | centos-upgrade-thunderbirdcentos-upgrade-thunderbird-debuginfocentos-upgrade-thunderbird-debugsource | Oct 20, 2022 | Sep 26, 2022 |
| Debian | debian-upgrade-thunderbird | Jul 30, 2024 | Dec 22, 2022 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-91_13_1 | Sep 1, 2022 | Aug 31, 2022 | |
| Oracle_linux | — | oracle-linux-upgrade-thunderbird | Sep 29, 2022 | Aug 31, 2022 |
| Redhat_linux | redhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginforedhat-upgrade-thunderbird-debugsource | Oct 20, 2022 | Sep 26, 2022 | |
| Rocky_linux | rocky-upgrade-thunderbirdrocky-upgrade-thunderbird-debuginforocky-upgrade-thunderbird-debugsource | Mar 12, 2024 | Dec 22, 2022 | |
| Suse | — | suse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Oct 26, 2022 | Sep 15, 2022 |
| Ubuntu | ubuntu-upgrade-thunderbird | Oct 8, 2022 | Sep 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub