CVE-2021-43542: Medium severity thunderbird vulnerability
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-43542.
Which software versions are affected by this vulnerability?
This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by using XMLHttpRequest to probe error messages for loading external protocols, allowing them to identify installed applications.
What is the severity level of this vulnerability?
This vulnerability has a severity level of medium.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [link1](https://bugzilla.mozilla.org/show_bug.cgi?id=1723281), [link2](https://www.mozilla.org/en-US/security/advisories/mfsa2021-54/), [link3](https://www.mozilla.org/en-US/security/advisories/mfsa2021-52/).