CVE-2021-38497: Medium severity thunderbird vulnerability
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What vulnerability is described in CVE-2021-38497?
CVE-2021-38497 describes a vulnerability in Firefox, Thunderbird, and Firefox ESR that allows for plain-text validation message overlay and possible user confusion and spoofing attacks.
Which software versions are affected by CVE-2021-38497?
Firefox versions before 93, Thunderbird versions before 91.2, and Firefox ESR versions before 91.2 are affected by CVE-2021-38497.
What is the severity rating of CVE-2021-38497?
The severity rating of CVE-2021-38497 is medium with a score of 6.5.
How can I fix CVE-2021-38497?
To fix CVE-2021-38497, update to Firefox version 93 or higher, Thunderbird version 91.2 or higher, or Firefox ESR version 91.2 or higher.
Where can I find more information about CVE-2021-38497?
More information about CVE-2021-38497 can be found at the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1726621), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2021-47/), [Mozilla Security Advisories](https://www.mozilla.org/security/advisories/mfsa2021-43/).