CVE Vulnerabilities

CVE-2022-45414

Published: Dec 22, 2022 | Modified: Apr 15, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was shown in the composer window. These issues could have given an attacker additional capabilities when targetting releases that did not yet have a fix for CVE-2022-3033 which was reported around three months ago. This vulnerability affects Thunderbird < 102.5.1.

Affected Software

NameVendorStart VersionEnd Version
ThunderbirdMozilla*102.5.1 (excluding)
Red Hat Enterprise Linux 7RedHatthunderbird-0:102.6.0-2.el7_9*
Red Hat Enterprise Linux 8RedHatthunderbird-0:102.6.0-2.el8_7*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatthunderbird-0:102.6.0-2.el8_1*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatthunderbird-0:102.6.0-2.el8_2*
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceRedHatthunderbird-0:102.6.0-2.el8_2*
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsRedHatthunderbird-0:102.6.0-2.el8_2*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatthunderbird-0:102.6.0-2.el8_4*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatthunderbird-0:102.6.0-2.el8_6*
Red Hat Enterprise Linux 9RedHatthunderbird-0:102.6.0-2.el9_1*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatthunderbird-0:102.6.0-2.el9_0*
ThunderbirdUbuntubionic*
ThunderbirdUbuntudevel*
ThunderbirdUbuntufocal*
ThunderbirdUbuntujammy*
ThunderbirdUbuntukinetic*
ThunderbirdUbuntulunar*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuxenial*

References