cbcvebase.
CVE-2022-3032
published 2022-12-22

CVE-2022-3032: When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the…

PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.66%
47.6th percentile
When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianthunderbird< thunderbird 1:102.2.1-1 (bookworm)thunderbird 1:102.2.1-1 (bookworm)
mozillafirefox
mozillathunderbird< 91.13.191.13.1
mozillathunderbird>= 0 < 1:102.2.1-11:102.2.1-1
mozillathunderbird>= 0 < 1:102.2.1-11:102.2.1-1
mozillathunderbird>= 0 < 1:102.2.1-11:102.2.1-1
mozillathunderbird>= 0 < 1:102.2.2+build1-0ubuntu0.18.04.11:102.2.2+build1-0ubuntu0.18.04.1
mozillathunderbird>= 0 < 1:102.2.2+build1-0ubuntu0.20.04.11:102.2.2+build1-0ubuntu0.20.04.1
mozillathunderbird>= 0 < 1:102.2.2+build1-0ubuntu0.22.04.11:102.2.2+build1-0ubuntu0.22.04.1
mozillathunderbird>= 102.0 < 102.2.1102.2.1
mozillathunderbird>= unspecified < 102.2.1102.2.1
mozillathunderbird>= unspecified < 91.13.191.13.1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.