First published: Tue May 03 2022(Updated: )
An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <91.9 | 91.9 |
Firefox | <100.0 | |
Firefox ESR | <91.9 | |
Thunderbird | <91.9 | |
Firefox | <100 | 100 |
Firefox ESR | <91.9 | 91.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-29911 has been classified as high severity due to its potential to allow script execution without necessary permissions.
To mitigate CVE-2022-29911, users should upgrade Mozilla Thunderbird to version 91.9 or later, and Firefox to version 100 or later.
CVE-2022-29911 affects Thunderbird versions prior to 91.9, Firefox ESR versions prior to 91.9, and Firefox versions prior to 100.
The impact of CVE-2022-29911 includes the potential for unauthorized script execution in affected versions.
Yes, CVE-2022-29911 affects both Mozilla Firefox and Mozilla Thunderbird in specific versions.