CVE-2022-45420: Medium severity thunderbird vulnerability
Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks.
Other sources
Using tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-45420.
What is the impact of CVE-2022-45420?
The vulnerability could allow an attacker to render iframe contents outside of the boundaries, potentially leading to user confusion or spoofing attacks.
Which software versions are affected by CVE-2022-45420?
Firefox ESR versions earlier than 102.5, Thunderbird versions earlier than 102.5, and Firefox versions earlier than 107 are affected.
How serious is CVE-2022-45420?
The severity of CVE-2022-45420 is rated as medium with a CVSS score of 6.5.
How can I fix CVE-2022-45420?
Update Firefox ESR to version 102.5 or later, Thunderbird to version 102.5 or later, and Firefox to version 107 or later to mitigate the vulnerability.