Mozilla · Thunderbird · CVE-2022-36315
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 103
Firefox ESR (affected versions not specified)
Thunderbird (affected versions not specified)
**Description**
The issue is related to errors in resource management when loading a script with Subresource Integrity. Attackers with injection capabilities could reuse previously cached entries with incorrect integrity metadata, potentially impacting the confidentiality and integrity of protected information.
**Recommendations**
For Firefox versions prior to 103, update to version 103 or later to resolve the issue.
For Firefox ESR, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Thunderbird, at the moment, there is no information about a newer version that contains a fix for this vulnerability.