CVE-2021-43528
Summary
| CVE | CVE-2021-43528 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-08 22:15:00 UTC |
| Updated | 2022-12-09 15:30:00 UTC |
| Description | Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159549 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-5045)
- 159550 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-5046)
- 178983 Debian Security Update for thunderbird (DSA 5034-1)
- 178986 Debian Security Update for thunderbird (DLA 2874-1)
- 184866 Debian Security Update for thunderbird (CVE-2021-43528)
- 198641 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5248-1)
- 198643 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5246-1)
- 239938 Red Hat Update for thunderbird (RHSA-2021:5046)
- 239939 Red Hat Update for thunderbird (RHSA-2021:5048)
- 239940 Red Hat Update for thunderbird (RHSA-2021:5045)
- 239941 Red Hat Update for thunderbird (RHSA-2021:5047)
- 376144 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-54)
- 502382 Alpine Linux Security Update for thunderbird
- 505449 Alpine Linux Security Update for thunderbird
- 710585 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202208-14)
- 751542 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:4150-1)
- 751566 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1635-1)
- 940397 AlmaLinux Security Update for thunderbird (ALSA-2021:5045)
- 960881 Rocky Linux Security Update for thunderbird (RLSA-2021:5045)