CVE-2021-38509: Medium severity thunderbird vulnerability
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2021-38509.
Which software is affected by this vulnerability?
This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
How can an attacker exploit this vulnerability?
By performing an unusual sequence of attacker-controlled events, the attacker can display a Javascript alert() dialog with arbitrary contents on an uncontrolled webpage of their choosing.
What is the severity of CVE-2021-38509?
The severity of CVE-2021-38509 is medium.
Where can I find more information about CVE-2021-38509?
More information about CVE-2021-38509 can be found at the following references: [Reference 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1718571), [Reference 2](https://www.mozilla.org/en-US/security/advisories/mfsa2021-49/), [Reference 3](https://lists.debian.org/debian-lts-announce/2021/12/msg00030.html).