CVE-2022-1197

MEDIUM

Thunderbird < 91.8 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. Revocation statements that used another revocation reason, or that didn't specify a revocation reason, were unaffected. This vulnerability affects Thunderbird < 91.8.

References (2)

Core 2
Core References
Issue Tracking, Permissions Required, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1754985

Scores

CVSS v3 5.4
EPSS 0.0024
EPSS Percentile 47.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
mozilla/thunderbird < 91.8
Published Dec 22, 2022
Tracked Since Feb 18, 2026