Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-43528

Опубликовано: 07 дек. 2021
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2021:504609.12.2021
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2021:504509.12.2021
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsthunderbirdFixedRHSA-2021:505509.12.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportthunderbirdFixedRHSA-2021:504709.12.2021
Red Hat Enterprise Linux 8.4 Extended Update SupportthunderbirdFixedRHSA-2021:504809.12.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-281
https://bugzilla.redhat.com/show_bug.cgi?id=2030137Mozilla: JavaScript unexpectedly enabled for the composition area

EPSS

Процентиль: 75%
0.0086
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

CVSS3: 6.5
nvd
около 4 лет назад

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

CVSS3: 6.5
debian
около 4 лет назад

Thunderbird unexpectedly enabled JavaScript in the composition area. T ...

CVSS3: 6.5
github
около 4 лет назад

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

CVSS3: 6.5
fstec
около 4 лет назад

Уязвимость почтового клиента Thunderbird, связанная с небезопасным управлением привилегиями, позволяющая нарушителю обойти ограничения на выполнение JavaScript

EPSS

Процентиль: 75%
0.0086
Низкий

6.3 Medium

CVSS3