CVE-2021-43528 - log back

CVE-2021-43528 created at 07 Dec 2021 20:05:23
Severity
+ Low
Remote
+ Remote
Type
+ Arbitrary code execution
Description
+ Thunderbird before version 91.4.0 unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities.
References
+ https://www.mozilla.org/security/advisories/mfsa2021-54/
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1742579
Notes