Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w45-xx62-4547

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.

EPSS

Процентиль: 48%
0.00254
Низкий

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 5 лет назад

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.

CVSS3: 5.9
redhat
больше 5 лет назад

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.

CVSS3: 5.9
nvd
больше 5 лет назад

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.

CVSS3: 5.9
debian
больше 5 лет назад

If an attacker intercepts Thunderbird's initial attempt to perform aut ...

EPSS

Процентиль: 48%
0.00254
Низкий

Дефекты

CWE-522