
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-1197 is a security vulnerability discovered in Mozilla Thunderbird affecting versions prior to 91.8. The vulnerability was identified by Thunderbird user Johannes König and was disclosed on April 5, 2022. The issue relates to OpenPGP key management where Thunderbird failed to properly handle revoked keys that specified key compromise as the revocation reason (Mozilla Advisory).
The vulnerability occurs when importing a revoked key that specified key compromise as the revocation reason. In such cases, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. It's important to note that revocation statements that used another revocation reason, or that didn't specify a revocation reason, were unaffected by this vulnerability. The issue has been assigned a moderate severity rating (Mozilla Advisory).
The impact of this vulnerability is considered moderate as it could potentially lead to security issues in OpenPGP key management. When a compromised key is imported, the failure to properly update the revocation status could result in continued trust of a key that should have been marked as compromised (Mozilla Advisory).
The vulnerability has been fixed in Thunderbird version 91.8. Users are advised to upgrade to this version or later to address the security issue. No specific workarounds were provided for users unable to upgrade immediately (Mozilla Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."