CVE-2022-3034: Medium severity thunderbird vulnerability
When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document.
Other sources
When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this Thunderbird issue?
The vulnerability ID for this Thunderbird issue is CVE-2022-3034.
What software versions are affected by this vulnerability?
This vulnerability affects Thunderbird versions prior to 91.13.1 and versions prior to 102.2.1.
What is the severity of CVE-2022-3034?
The severity of CVE-2022-3034 is medium with a CVSS score of 4.
Is there a fix available for this vulnerability?
Yes, the fix for this vulnerability is available in Thunderbird version 91.13.1 and Thunderbird version 102.2.1.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found in Mozilla's security advisories MFSA2022-39 and MFSA2022-38.