Related Vulnerabilities: CVE-2021-43543  

A security issue has been found in Firefox before version 95 and Thunderbird before version 91.4.0. Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content.

Severity Medium

Remote Yes

Type Sandbox escape

Description

A security issue has been found in Firefox before version 95 and Thunderbird before version 91.4.0. Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content.

AVG-2608 thunderbird 91.3.2-2 High Vulnerable

AVG-2606 firefox 94.0.2-2 95.0-1 High Fixed

https://www.mozilla.org/security/advisories/mfsa2021-52/
https://www.mozilla.org/security/advisories/mfsa2021-54/
https://bugzilla.mozilla.org/show_bug.cgi?id=1738418