CVE-2022-31738: Medium severity thunderbird vulnerability
Published May 31, 2022
·Updated
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks.
Affected Software
6 affected componentsFixes available
Mozilla Thunderbird<91.10
91.10
Mozilla Firefox<101
Mozilla Firefox ESR<91.10
Mozilla Thunderbird<91.10
Mozilla Firefox<101
101
Mozilla Firefox ESR<91.10
91.10
Event History
May 31, 2022
CVE Published
via Mozilla·12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-31738?
CVE-2022-31738 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2022-31738?
To mitigate CVE-2022-31738, update to the latest version of Firefox or Thunderbird that resolves this issue.
3
Which versions of Firefox are affected by CVE-2022-31738?
CVE-2022-31738 affects Firefox versions prior to 101 and Firefox ESR versions prior to 91.10.
4
Can CVE-2022-31738 lead to user spoofing attacks?
Yes, CVE-2022-31738 can potentially enable spoofing attacks due to confusion around fullscreen state.
5
Is Firefox ESR impacted by CVE-2022-31738?
Yes, CVE-2022-31738 impacts Firefox ESR versions prior to 91.10.