CVE-2022-40959: Medium severity thunderbird vulnerability
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-40959?
The severity of CVE-2022-40959 is high.
Which software versions are affected by CVE-2022-40959?
CVE-2022-40959 affects Mozilla Thunderbird up to version 102.3, Mozilla Firefox up to version 105, and Mozilla Firefox ESR up to version 102.3.
How can I fix CVE-2022-40959?
To fix CVE-2022-40959, update to the latest versions of Mozilla Thunderbird, Mozilla Firefox, or Mozilla Firefox ESR.
Where can I find more information about CVE-2022-40959?
You can find more information about CVE-2022-40959 in the following references: [link1](https://bugzilla.mozilla.org/show_bug.cgi?id=1782211), [link2](https://www.mozilla.org/en-US/security/advisories/mfsa2022-42/), [link3](https://www.mozilla.org/en-US/security/advisories/mfsa2022-40/)
What is the vulnerability description of CVE-2022-40959?
CVE-2022-40959 is a vulnerability that occurs during iframe navigation, where certain pages do not have their FeaturePolicy fully initialized, leading to a bypass that leaks device permissions into untrusted subdocuments.