CVE-2021-38508: Medium severity thunderbird vulnerability
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-38508?
CVE-2021-38508 is a vulnerability that could potentially trick users into granting permissions by obscuring permission prompts with form validity messages.
Which software products are affected by CVE-2021-38508?
Firefox ESR < 91.3, Thunderbird < 91.3, and Firefox < 94 are affected by CVE-2021-38508.
What is the severity of CVE-2021-38508?
CVE-2021-38508 has a severity level of medium (4).
How can I fix CVE-2021-38508?
Update your Firefox ESR to version 91.3 or newer, Thunderbird to version 91.3 or newer, or Firefox to version 94 or newer to fix CVE-2021-38508.
Where can I find more information about CVE-2021-38508?
You can find more information about CVE-2021-38508 on the Mozilla Bugzilla and Mozilla Security Advisories websites.