An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101.
2022-12-22T20:15:29.733
2025-04-15T19:15:59.040
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 101.0 | Yes |
Application | mozilla | firefox_esr | < 91.11 | Yes |
Application | mozilla | thunderbird | < 91.11 | Yes |