CVE-2018-12383: Medium severity Mozilla Thunderbird vulnerability
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-12383?
The severity of CVE-2018-12383 is classified as medium.
How do I fix CVE-2018-12383?
To fix CVE-2018-12383, users should update to Firefox 62 or later, or replace older installations of Thunderbird and Firefox ESR with versions 60.2.1 and above.
What software is affected by CVE-2018-12383?
CVE-2018-12383 affects Mozilla Firefox versions prior to 62, Thunderbird versions prior to 60.2.1, and Firefox ESR versions prior to 60.2.1.
Can I still access my passwords after setting a master password with CVE-2018-12383?
Yes, an unencrypted copy of previously saved passwords can still be accessed even after setting a master password due to this vulnerability.
Is it safe to continue using affected versions of Firefox and Thunderbird in light of CVE-2018-12383?
No, it is not safe to continue using affected versions as they expose saved passwords to potential unauthorized access.