CVE-2021-23961: High severity thunderbird vulnerability
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-23961?
CVE-2021-23961 refers to a vulnerability that could expose both an internal network's hosts and services running on the user's local machine.
Which software are affected by CVE-2021-23961?
Mozilla Thunderbird (up to version 78.10), Mozilla Firefox (up to version 85), and Mozilla Firefox ESR (up to version 78.10) are affected by CVE-2021-23961.
What is the severity level of CVE-2021-23961?
CVE-2021-23961 has a severity level of medium.
How can I fix CVE-2021-23961?
Ensure that you have updated Mozilla Thunderbird, Mozilla Firefox, and Mozilla Firefox ESR to the latest versions available, as specified in the remedy section.
Where can I find more information about CVE-2021-23961?
You can refer to the following references for more information about CVE-2021-23961: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1677940), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2021-14/), and [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2021-03/).