CVE-2022-3155
Last modified
CVE-2022-3155 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Thunderbird | < 102.3 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1789061Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-42/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1789061Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-42/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1789061Issue Tracking, Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3155?
How severe is CVE-2022-3155?
How do I fix CVE-2022-3155?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31544The meerstein/rbtm repository through 1.5 on GitHub allows a…9.3
- CVE-2022-31545The ml-inory/ModelConverter repository through 2021-04-26 on…9.3
- CVE-2022-31546The nlpweb/glance repository through 2014-06-27 on GitHub al…9.3
- CVE-2022-31547The noamezekiel/sphere repository through 2020-05-31 on GitH…9.3
- CVE-2022-31548The nrlakin/homepage repository through 2017-03-06 on GitHub…9.3
- CVE-2022-31549The olmax99/helm-flask-celery repository before 2022-05-25 o…9.3
- CVE-2022-31550The olmax99/pyathenastack repository through 2019-11-08 on G…9.3
- CVE-2022-31551The pleomax00/flask-mongo-skel repository through 2012-11-01…9.3
- CVE-2022-31552The project-anuvaad/anuvaad-corpus repository through 2020-1…9.3
- CVE-2022-31553The rainsoupah/sleep-learner repository through 2021-02-21 o…9.3
- CVE-2022-31554The rohitnayak/movie-review-sentiment-analysis repository th…9.3
- CVE-2022-31555The romain20100/nursequest repository through 2018-02-22 on …9.3
Are you affected by CVE-2022-3155?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
