Vulnerability Intelligence Report
CVE-2021-38503
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
EPSS Probability:3.83%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Mozilla | Firefox | unspecified < 94 (affected) |
| Mozilla | Thunderbird | unspecified < 91.3 (affected) |
| Mozilla | Firefox ESR | unspecified < 91.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.830%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Mozilla Corporation · Vendor · USA |
| Reserved | 2021-08-10T00:00:00 |
| Published | 2021-12-08T21:22:07 |
| Last Updated | 2024-08-04T01:44:23 |
Community Chatter & Buzz