If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 18, 2018 |
| Centos_linux | — | Upgrade firefox-debuginfoUpgrade thunderbird-debuginfoUpgrade firefoxUpgrade thunderbird | Oct 2, 2018 | Sep 5, 2018 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Sep 25, 2018 | Sep 5, 2018 |
| Freebsd | — | Upgrade thunderbirdUpgrade linux-firefoxUpgrade waterfoxUpgrade firefoxUpgrade libxulUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade linux-thunderbirdUpgrade firefox-esr | Sep 6, 2018 | Sep 5, 2018 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird. | Oct 3, 2018 | Oct 2, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade firefox | Nov 6, 2018 | Oct 18, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade firefox | Nov 8, 2018 | Oct 18, 2018 |
| Mfsa2018 20 | — | Upgrade to Mozilla Firefox version 62.0 | Sep 6, 2018 | Sep 5, 2018 |
| Mfsa2018 23 | — | Upgrade to Mozilla Firefox ESR version 60.2.1 | Sep 24, 2018 | Sep 21, 2018 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 60.2.1 | Oct 5, 2018 | Oct 4, 2018 |
| Oracle Solaris | — | Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4Upgrade web/browser/firefox to version 60.5.0-11.4.6.0.1.4.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 60.5.0-11.4.6.0.1.4.0 on Solaris 11.4Upgrade mail/thunderbird to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4 | Feb 20, 2019 | Oct 18, 2018 |
| Oracle_linux | — | Upgrade firefoxUpgrade thunderbird | Sep 28, 2018 | Sep 5, 2018 |
| Redhat_linux | — | No solution existsUpgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade firefox-debuginfoUpgrade firefox | Sep 28, 2018 | Sep 27, 2018 |
| Suse | — | Upgrade mozilla-nss-toolsUpgrade mozilla-nss-certsUpgrade mozilla-nss-32bitUpgrade libfreebl3Upgrade mozilla-nss-develUpgrade MozillaFirefoxUpgrade MozillaThunderbird-buildsymbolsUpgrade MozillaThunderbird-translations-otherUpgrade mozilla-nss-sysinit-32bitUpgrade mozilla-nsprUpgrade libsoftokn3Upgrade mozilla-nspr-32bitUpgrade libsoftokn3-hmacUpgrade MozillaFirefox-translations-otherUpgrade libfreebl3-32bitUpgrade libsoftokn3-32bitUpgrade mozilla-nssUpgrade apache2-mod_nssUpgrade mozillafirefox-branding-sleUpgrade mozilla-nspr-develUpgrade MozillaThunderbird-translations-commonUpgrade mozilla-nss-certs-32bitUpgrade mozillafirefox-buildsymbolsUpgrade MozillaFirefox-translations-commonUpgrade mozilla-nss-sysinitUpgrade libsoftokn3-hmac-32bitUpgrade libfreebl3-hmac-32bitUpgrade MozillaThunderbirdUpgrade MozillaFirefox-develUpgrade libfreebl3-hmacUpgrade mozillafirefox-branding-upstream | Sep 25, 2018 | Sep 5, 2018 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefox | Sep 19, 2018 | Sep 5, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub