Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2022-3033

8.1 · HIGH
Published Dec 22, 2022 mozilla CWE-79 EPSS 0.77% (53th pctl)

Overview

CVE-2022-3033 is a high-severity vulnerability affecting mozilla thunderbird. It was published on December 22, 2022 and has a CVSS 3.1 base score of 8.1 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"</code> attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL, regardless of the configuration to block remote content. In combination with certain other HTML elements and attributes in the email, it was possible to execute JavaScript code included in the message in the context of the message compose document. The JavaScript code was able to perform actions including, but probably not limited to, read and modify the contents of the message compose document, including the quoted original message, which could potentially contain the decrypted plaintext of encrypted data in the crafted email. The contents could then be transmitted to the network, either to the URL specified in the META refresh tag, or to a different URL, as the JavaScript code could modify the URL specified in

Remediation

Check the references section for vendor advisories and patches from mozilla. Update thunderbird to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
mozilla thunderbird >= 0, < 91.13.1 Affected

Frequently Asked Questions

What is CVE-2022-3033?

CVE-2022-3033 is a high-severity vulnerability affecting mozilla thunderbird. It was published on December 22, 2022 and has a CVSS 3.1 base score of 8.1 (HIGH).

How severe is CVE-2022-3033?

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2022-3033?

Check the references section for vendor advisories and patches from mozilla. Update thunderbird to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2022-3033?

CyberStrike's AI-powered security agents can automatically detect CVE-2022-3033 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.