The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esrUpgrade librewolfUpgrade firefoxUpgrade thunderbird | Aug 22, 2024 | Dec 22, 2022 |
| Mfsa2022 01 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 96.0 | Jan 12, 2022 | Jan 11, 2022 |
| Mfsa2022 02 | — | Upgrade to Mozilla Firefox ESR version 91.5Upgrade to the latest version of Mozilla Firefox | Jan 12, 2022 | Jan 11, 2022 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.5Upgrade to the latest version of Mozilla Thunderbird | Jan 12, 2022 | Jan 11, 2022 |
| Suse | — | Upgrade MozillaThunderbird-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefoxUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-translations-common | Feb 12, 2022 | Jan 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub