CVE-2022-22754: Medium severity thunderbird vulnerability
Published Feb 8, 2022
·Updated
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions.
Affected Software
6 affected componentsFixes available
Mozilla Thunderbird<91.6
91.6
Mozilla Firefox<97.0
Mozilla Firefox ESR<91.6
Mozilla Thunderbird<91.6
Mozilla Firefox ESR<91.6
91.6
Mozilla Firefox<97
97
Event History
Feb 8, 2022
CVE Published
via Mozilla·12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22754.
2
Which software versions are affected by this vulnerability?
This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
3
What is the severity of CVE-2022-22754?
The severity of CVE-2022-22754 is high with a CVSS score of 6.5.
4
How can I fix the vulnerability in Firefox?
To fix the vulnerability in Firefox, update to version 97 or later.
5
How can I fix the vulnerability in Thunderbird?
To fix the vulnerability in Thunderbird, update to version 91.6 or later.
6
How can I fix the vulnerability in Firefox ESR?
To fix the vulnerability in Firefox ESR, update to version 91.6 or later.