CVE-2022-1520
MEDIUMMozilla Thunderbird < 91.9 - Origin Validation Error
Title source: ruleDescription
When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B. This vulnerability affects Thunderbird < 91.9.
Scores
CVSS v3
4.3
EPSS
0.0010
EPSS Percentile
26.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-346
Status
published
Affected Products (1)
mozilla/thunderbird
< 91.9
Timeline
Published
Dec 22, 2022
Tracked Since
Feb 18, 2026