Insufficient Granularity of Access Control Affecting thunderbird package, versions [,137.0.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-THUNDERBIRD-9788172
  • published21 Apr 2025
  • disclosed15 Apr 2025
  • creditDario Weißer

Introduced: 15 Apr 2025

NewCVE-2025-3522  (opens in a new tab)
CWE-1220  (opens in a new tab)

How to fix?

Upgrade thunderbird to version 137.0.2 or higher.

Overview

Affected versions of this package are vulnerable to Insufficient Granularity of Access Control due to the handling of the X-Mozilla-External-Attachment-URL header. An attacker can leak hashed Windows credentials by crafting a malicious attachment URL that references internal resources such as chrome:// or SMB share file:// links.

CVSS Base Scores

version 4.0
version 3.1