First published: Mon Apr 19 2021(Updated: )
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 | |
Thunderbird | <78.10 | 78.10 |
Firefox | <88.0 | |
Firefox ESR | <78.10 | |
Thunderbird | <78.10 | |
Firefox | <88 | 88 |
Firefox ESR | <78.10 | 78.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-23998 has a moderate severity rating as it can mislead users by displaying a secure lock icon on an insecure HTTP page.
To fix CVE-2021-23998, upgrade to Mozilla Thunderbird or Firefox ESR version 78.10 or later.
CVE-2021-23998 affects Mozilla Thunderbird versions prior to 78.10 and Mozilla Firefox ESR versions prior to 78.10.
The impact of CVE-2021-23998 is that it can create a false sense of security for users by displaying a secure lock symbol on an unsecured HTTP page.
CVE-2021-23998 is potentially exploitable remotely as it arises from the way new windows handle navigation between secure and insecure content.