ZeroHour

CVE-2022-1520

CVSS 3.1
4.3 medium
EPSS
<1%p18
Published
()
Modified
Description

When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B. This vulnerability affects Thunderbird < 91.9.

Vendors
mozilla
Products
thunderbird
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.