Thunderbird unexpectedly enabled JavaScript in the...
Moderate severity
Unreviewed
Published
Dec 9, 2021
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Dec 8, 2021
Published to the GitHub Advisory Database
Dec 9, 2021
Last updated
Jan 29, 2023
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.
References