PT-2022-4567 · Mozilla+10 · Thunderbird+10

Sarah Jamie Lewis

·

Published

2022-08-31

·

Updated

2024-06-15

·

CVE-2022-3033

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 102.2.1 Thunderbird versions prior to 91.13.1
Description The issue is related to how Thunderbird handles certain HTML emails. If a user replies to a crafted HTML email containing a meta tag with the http-equiv="refresh" attribute and a content attribute specifying a URL, Thunderbird initiates a network request to that URL, regardless of the configuration to block remote content. This can lead to the execution of JavaScript code included in the message, allowing actions such as reading and modifying the message compose document, including potentially decrypted plaintext of encrypted data. The contents could then be transmitted to the network. Users who have changed the default message body display setting to 'simple html' or 'plain text' are not affected.
Recommendations For Thunderbird versions prior to 102.2.1, update to version 102.2.1 or later. For Thunderbird versions prior to 91.13.1, update to version 91.13.1 or later. As a temporary workaround, consider changing the default Message Body display setting to 'simple html' or 'plain text' to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:6708
ALSA-2022:6717
ALT-PU-2022-2570
ALT-PU-2022-2931
ALT-PU-2023-1137
ALT-PU-2023-4335
BDU:2022-05444
CESA-2022_6708
CVE-2022-3033
OPENSUSE-SU-2022_3281-1
OPENSUSE-SU-2024:12299-1
RHSA-2022:6708
RHSA-2022:6710
RHSA-2022:6713
RHSA-2022:6715
RHSA-2022:6716
RHSA-2022:6717
RHSA-2022_6708
RHSA-2022_6710
RHSA-2022_6717
RLSA-2022:6708
SUSE-SU-2022:3281-1
USN-5663-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu