CVE-2022-3032

Public on 2022-11-29
Modified on 2024-02-09
Description
When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.4
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core thunderbird 2022-12-01 ALAS2-2022-1900 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.4 /AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NVD CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N