The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade librewolfUpgrade firefox-esrUpgrade thunderbirdUpgrade firefox | Aug 22, 2024 | Dec 22, 2022 |
| Mfsa2022 01 | — | Upgrade to Mozilla Firefox version 96.0Upgrade to the latest version of Mozilla Firefox | Jan 12, 2022 | Jan 11, 2022 |
| Mfsa2022 02 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 91.5 | Jan 12, 2022 | Jan 11, 2022 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.5Upgrade to the latest version of Mozilla Thunderbird | Jan 12, 2022 | Jan 11, 2022 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaThunderbirdUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefoxUpgrade mozillafirefox-branding-upstream | Feb 12, 2022 | Jan 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub