A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38473.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "104.0"
}
]
},
{
"events": [
{
"introduced": "102.0"
},
{
"fixed": "102.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "91.13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "91.13"
}
]
},
{
"events": [
{
"introduced": "102.0"
},
{
"fixed": "102.2"
}
]
}
]