Missing Encryption of Sensitive Data Affecting thunderbird package, versions [,115.8.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Encryption of Sensitive Data vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-THUNDERBIRD-6417981
  • published7 Mar 2024
  • disclosed4 Mar 2024
  • creditUnknown

Introduced: 4 Mar 2024

CVE-2024-1936  (opens in a new tab)
CWE-311  (opens in a new tab)

How to fix?

Upgrade thunderbird to version 115.8.1 or higher.

Overview

Affected versions of this package are vulnerable to Missing Encryption of Sensitive Data due to the mishandling of encrypted email subjects within the local cache. An attacker can inadvertently cause the encrypted subject of an email to be incorrectly and permanently assigned to another email message. This could lead to the accidental leakage of confidential information when replying to the contaminated email message.

Workaround

This vulnerability can be mitigated by using the repair folder functionality, which is available from the context menu of email folders, to erase incorrect subject assignments.

CVSS Scores

version 3.1