CVE-2021-38503: Critical severity thunderbird vulnerability
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2021-38503.
Which software products are affected by this vulnerability?
This vulnerability affects Firefox versions earlier than 94, Thunderbird versions earlier than 91.3, and Firefox ESR versions earlier than 91.3.
What is the severity of CVE-2021-38503?
CVE-2021-38503 has a severity rating of critical.
How can I fix this vulnerability?
To fix this vulnerability, update your Firefox to version 94 or later, Thunderbird to version 91.3 or later, or Firefox ESR to version 91.3 or later.
Where can I find more information about CVE-2021-38503?
You can find more information about CVE-2021-38503 in the following references: [link1], [link2], [link3].