Security Advisory

CVE-2021-4140

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-12-22 00:00:00
Last updated 2025-04-16 15:55:20
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.