CVE-2021-43528

Description

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.86

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Mozilla Thunderbird (91) (91.4.0)Windows
Multiple vulnerabilities fixed in Mozilla Thunderbird (91) (x64) (91.4.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (91.4.0)Mac
Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 91.3.0Mac
(RHSA-2021:5045) thunderbird security update thunderbird-91.4.0-2.el8_5.x86_64.rpmLinux
(RHSA-2021:5045) thunderbird security update thunderbird-debugsource-91.4.0-2.el8_5.x86_64.rpmLinux
(RHSA-2021:5046) thunderbird security update thunderbird-91.4.0-3.el7_9.x86_64.rpmLinux
Thunderbird update (ELSA-2021-5045) thunderbird-91.4.0-2.0.1.el8_5.x86_64.rpmLinux
thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb10u1_i386.debLinux
thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb10u1_amd64.debLinux
thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb11u1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.20.04.1_amd64.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-322725Mozilla Thunderbird (91) (91.4.0)
PATCH-322726Mozilla Thunderbird (91) (x64) (91.4.0)
PATCH-611353Mozilla Thunderbird For Mac (128.12.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234