By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade librewolfUpgrade firefoxUpgrade firefox-esrUpgrade thunderbird | Aug 22, 2024 | Oct 1, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Dec 10, 2020 | Oct 1, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 1, 2020 |
| Centos_linux | — | Upgrade firefoxUpgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade firefox-debugsourceUpgrade firefox-debuginfo | Sep 25, 2020 | Sep 24, 2020 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Sep 30, 2020 | Sep 30, 2020 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird-bin. | Oct 19, 2020 | Oct 1, 2020 |
| Mfsa2020 42 | — | Upgrade to Mozilla Firefox version 81.0 | Sep 23, 2020 | Sep 22, 2020 |
| Mfsa2020 43 | — | Upgrade to Mozilla Firefox ESR version 78.3 | Sep 23, 2020 | Sep 22, 2020 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 78.3 | Sep 25, 2020 | Sep 22, 2020 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade web/browser/firefox to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4 | Jan 19, 2021 | Oct 1, 2020 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Sep 25, 2020 | Sep 22, 2020 |
| Redhat_linux | — | Upgrade firefoxNo solution existsUpgrade thunderbirdUpgrade firefox-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debugsource | Sep 25, 2020 | Sep 24, 2020 |
| Suse | — | Upgrade mozilla-nspr-32bitUpgrade mozillathunderbird-translations-commonUpgrade mozilla-nspr-develUpgrade mozillafirefox-develUpgrade mozillafirefox-translations-commonUpgrade mozilla-nsprUpgrade mozillafirefox-translations-otherUpgrade mozillafirefox-branding-upstreamUpgrade mozillathunderbird-translations-otherUpgrade mozillathunderbirdUpgrade mozillafirefoxUpgrade mozillafirefox-buildsymbols | Sep 29, 2020 | Sep 24, 2020 |
| Ubuntu | — | Upgrade firefox | Sep 29, 2020 | Sep 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub