CVE-2021-23998: Medium severity thunderbird vulnerability
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-23998?
CVE-2021-23998 has a moderate severity rating as it can mislead users by displaying a secure lock icon on an insecure HTTP page.
How do I fix CVE-2021-23998?
To fix CVE-2021-23998, upgrade to Mozilla Thunderbird or Firefox ESR version 78.10 or later.
Which versions are affected by CVE-2021-23998?
CVE-2021-23998 affects Mozilla Thunderbird versions prior to 78.10 and Mozilla Firefox ESR versions prior to 78.10.
What is the impact of CVE-2021-23998 on users?
The impact of CVE-2021-23998 is that it can create a false sense of security for users by displaying a secure lock symbol on an unsecured HTTP page.
Is CVE-2021-23998 exploitable remotely?
CVE-2021-23998 is potentially exploitable remotely as it arises from the way new windows handle navigation between secure and insecure content.