CVE-2022-28286: Medium severity firefox esr vulnerability
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-28286?
CVE-2022-28286 refers to a vulnerability in Thunderbird and Firefox that could allow iframe contents to be rendered outside of its border, leading to user confusion or spoofing attacks.
Which software versions are affected by CVE-2022-28286?
CVE-2022-28286 affects Thunderbird versions less than 91.8, Firefox versions less than 99, and Firefox ESR versions less than 91.8.
How severe is CVE-2022-28286?
CVE-2022-28286 has a severity rating of 5.4, which is considered medium.
How can I fix CVE-2022-28286?
To fix CVE-2022-28286, update Thunderbird to version 91.8 or later, update Firefox to version 99 or later, or update Firefox ESR to version 91.8 or later.
Where can I find more information about CVE-2022-28286?
You can find more information about CVE-2022-28286 on the Mozilla website and Bugzilla.