CVE-2021-38507: Medium severity thunderbird vulnerability
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if a second encrypted port on the same IP address (e.g. port 8443) did not opt-in to opportunistic encryption; a network attacker could forward a connection from the browser to port 443 to port 8443, causing the browser to treat the content of port 8443 as same-origin with HTTP. This was resolved by disabling the Opportunistic Encryption feature, which had low usage.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-38507?
CVE-2021-38507 is a vulnerability in the Opportunistic Encryption feature of HTTP2 that allows a connection to be upgraded to TLS while retaining the visual properties of an HTTP connection.
Which software is affected by CVE-2021-38507?
CVE-2021-38507 affects Mozilla Firefox, Mozilla Firefox ESR, Mozilla Thunderbird, and Debian Linux.
What is the severity of CVE-2021-38507?
CVE-2021-38507 has a severity rating of 6.5 (high).
How can I fix CVE-2021-38507?
To fix CVE-2021-38507, it is recommended to update to the latest version of the affected software.
Where can I find more information about CVE-2021-38507?
You can find more information about CVE-2021-38507 in the references provided: Bugzilla, Mozilla Security Advisories, and Debian LTS Announce.