CVE Vulnerabilities

CVE-2021-43528

Improper Privilege Management

Published: Dec 08, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
6.3 LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
ThunderbirdMozilla*91.4.0 (excluding)
Red Hat Enterprise Linux 7RedHatthunderbird-0:91.4.0-3.el7_9*
Red Hat Enterprise Linux 8RedHatthunderbird-0:91.4.0-2.el8_5*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatthunderbird-0:91.4.0-2.el8_1*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatthunderbird-0:91.4.0-2.el8_2*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatthunderbird-0:91.4.0-2.el8_4*
ThunderbirdUbuntubionic*
ThunderbirdUbuntudevel*
ThunderbirdUbuntufocal*
ThunderbirdUbuntuhirsute*
ThunderbirdUbuntuimpish*
ThunderbirdUbuntujammy*
ThunderbirdUbuntukinetic*
ThunderbirdUbuntulunar*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuxenial*

Potential Mitigations

References