First published: Tue Nov 02 2021(Updated: )
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.3 | 91.3 |
<94 | 94 | |
<91.3 | 91.3 | |
<91.3 | 91.3 | |
Mozilla Firefox | <94.0 | |
Mozilla Firefox ESR | <91.3 | |
Mozilla Thunderbird | <91.3 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 115.4.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The CVE ID for this vulnerability is CVE-2021-38503.
This vulnerability affects Firefox versions earlier than 94, Thunderbird versions earlier than 91.3, and Firefox ESR versions earlier than 91.3.
CVE-2021-38503 has a severity rating of critical.
To fix this vulnerability, update your Firefox to version 94 or later, Thunderbird to version 91.3 or later, or Firefox ESR to version 91.3 or later.
You can find more information about CVE-2021-38503 in the following references: [link1], [link2], [link3].