Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45812
HistoryMar 10, 2024 - 2:43 a.m.

Sensitive Information Exposure

2024-03-1002:43:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
thunderbird
sensitive information exposure
email confidentiality

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Thunderbird is vulnerable to Sensitive Information Exposure. The vulnerability is due to the encrypted subject of an email message being incorrectly and permanently assigned to an arbitrary other email message in Thunderbird’s local cache. This could lead to the accidental leakage of confidential subject information to a third party when replying to the contaminated email message. While the update fixes the bug and prevents future message contamination, existing contaminations are not automatically repaired. Users are advised to use the repair folder functionality available from the context menu of email folders, which will erase incorrect subject assignments.