CVE-2018-5185Missing Encryption of Sensitive Data in Mozilla Thunderbird

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 44.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 13

Description

Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages8 packages

CVEListV5mozilla/thunderbirdunspecified52.8
NVDmozilla/thunderbird< 52.8.0
CVEListV5mozilla/thunderbird_esrunspecified52.8
Debianmozilla/thunderbird< 1:52.8.0-1+3

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04, Enterprise Linux 7.6, 7.5

🔴Vulnerability Details

3
GHSA
GHSA-jx89-4j89-fggc: Plaintext of decrypted emails can leak through by user submitting an embedded form2022-05-13
CVEList
CVE-2018-5185: Plaintext of decrypted emails can leak through by user submitting an embedded form2018-06-11
OSV
CVE-2018-5185: Plaintext of decrypted emails can leak through by user submitting an embedded form2018-06-11

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2018-05-25
Red Hat
Mozilla: Leaking plaintext through HTML forms2018-05-18
Debian
CVE-2018-5185: thunderbird - Plaintext of decrypted emails can leak through by user submitting an embedded fo...2018

💬Community

1
Bugzilla
CVE-2018-5185 Mozilla: Leaking plaintext through HTML forms2018-05-21
CVE-2018-5185 — Missing Encryption of Sensitive Data | cvebase