First published: Wed Aug 31 2022(Updated: )
When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
<102.2.1 | 102.2.1 | |
Mozilla Thunderbird | <91.13.1 | 91.13.1 |
<91.13.1 | 91.13.1 | |
Mozilla Thunderbird | <91.31.1 | |
Mozilla Thunderbird | >=102.0<102.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this Thunderbird issue is CVE-2022-3034.
This vulnerability affects Thunderbird versions prior to 91.13.1 and versions prior to 102.2.1.
The severity of CVE-2022-3034 is medium with a CVSS score of 4.
Yes, the fix for this vulnerability is available in Thunderbird version 91.13.1 and Thunderbird version 102.2.1.
More information about this vulnerability can be found in Mozilla's security advisories MFSA2022-39 and MFSA2022-38.