CVE-2018-12374: Infoleak
A flaw was found in Mozilla Thunderbird before version 52.9. Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field.
References: https://www.mozilla.org/en-US/security/advisories/mfsa2018-18/#CVE-2018-12374
Other sources
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9.
— Launchpad
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-12374?
CVE-2018-12374 is classified as a moderate severity vulnerability.
How do I fix CVE-2018-12374?
To fix CVE-2018-12374, upgrade Mozilla Thunderbird to version 52.9 or later.
Who is affected by CVE-2018-12374?
CVE-2018-12374 affects all versions of Mozilla Thunderbird before version 52.9.
What is the impact of CVE-2018-12374?
The impact of CVE-2018-12374 is that the plaintext of decrypted emails can be unintentionally leaked when submitting an embedded form.
Is there a workaround for CVE-2018-12374?
A temporary workaround for CVE-2018-12374 is to refrain from using forms in Thunderbird until the software is updated.