Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-28286
HistoryApr 06, 2022 - 12:00 a.m.

CVE-2022-28286

2022-04-0600:00:00
ubuntu.com
ubuntu.com
24
layout change
iframe contents
user confusion
spoofing attacks
thunderbird
firefox esr
unix

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

44.8%

Due to a layout change, iframe contents could have been rendered outside of
its border. This could have led to user confusion or spoofing attacks. This
vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR <
91.8.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchfirefox< 99.0+build2-0ubuntu0.18.04.2UNKNOWN
ubuntu20.04noarchfirefox< 99.0+build2-0ubuntu0.20.04.2UNKNOWN
ubuntu21.10noarchfirefox< 99.0+build2-0ubuntu0.21.10.2UNKNOWN
ubuntu22.04noarchfirefox< 1:1snap1-0ubuntu1UNKNOWN
ubuntu22.10noarchfirefox< 1:1snap1-0ubuntu1UNKNOWN
ubuntu23.04noarchfirefox< 1:1snap1-0ubuntu1UNKNOWN
ubuntu18.04noarchthunderbird< 1:91.8.1+build1-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchthunderbird< 1:91.8.1+build1-0ubuntu0.20.04.1UNKNOWN
ubuntu21.10noarchthunderbird< 1:91.8.1+build1-0ubuntu0.21.10.1UNKNOWN

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

44.8%