Improper Restriction of Rendered UI Layers or Frames Affecting thunderbird package, versions [,102.2.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (50th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-THUNDERBIRD-3014229
  • published2 Sept 2022
  • disclosed31 Aug 2022
  • creditSarah Jamie Lewis

Introduced: 31 Aug 2022

CVE-2022-3032  (opens in a new tab)
CWE-1021  (opens in a new tab)

How to fix?

Upgrade thunderbird to version 102.2.1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Restriction of Rendered UI Layers or Frames. When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example, images or videos, were not blocked. Instead, the network was accessed, and the objects were loaded and displayed.

CVSS Scores

version 3.1