CVE-2022-1520

MEDIUM

Mozilla Thunderbird < 91.9 - Origin Validation Error

Title source: rule

Description

When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B. This vulnerability affects Thunderbird < 91.9.

Scores

CVSS v3 4.3
EPSS 0.0010
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-346
Status published

Affected Products (1)

mozilla/thunderbird < 91.9

Timeline

Published Dec 22, 2022
Tracked Since Feb 18, 2026