CVE-2022-45414
Last modified
CVE-2022-45414 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was shown in the composer window. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was shown in the composer window. These issues could have given an attacker additional capabilities when targetting releases that did not yet have a fix for CVE-2022-3033 which was reported around three months ago. This vulnerability affects Thunderbird < 102.5.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Thunderbird | < 102.5.1 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1788096Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-50/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1788096Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-50/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-45414?
How severe is CVE-2022-45414?
How do I fix CVE-2022-45414?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-45409The garbage collector could have been aborted in several sta…8.8
- CVE-2022-4541The WordPress Visitors plugin for WordPress is vulnerable to…6.1
- CVE-2022-45410When a ServiceWorker intercepted a request with <code>FetchE…6.5
- CVE-2022-45411Cross-Site Tracing occurs when a server will echo a request …6.1
- CVE-2022-45412When resolving a symlink such as <code>file:///proc/self/fd/…8.8
- CVE-2022-45413Using the <code>S.browser_fallback_url parameter</code> para…6.1
- CVE-2022-45415When downloading an HTML file, if the title of the page was …7.8
- CVE-2022-45416Keyboard events reference strings like "KeyA" that were at f…6.5
- CVE-2022-45417Service Workers did not detect Private Browsing Mode correct…4.3
- CVE-2022-45418If a custom mouse cursor is specified in CSS, under certain …6.1
- CVE-2022-45419If the user added a security exception for an invalid TLS ce…6.5
- CVE-2022-4542The Compact WP Audio Player WordPress plugin before 1.9.8 do…5.4
Are you affected by CVE-2022-45414?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
