Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2874-1 thunderbird security update
Debian DSA Debian DSA DSA-5034-1 thunderbird security update
EUVD EUVD EUVD-2021-24954 Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.
Ubuntu USN Ubuntu USN USN-5248-1 Thunderbird vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00405}

epss

{'score': 0.00461}


cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2024-08-04T01:44:22.910Z

Reserved: 2021-08-10T00:00:00

Link: CVE-2021-38502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-03T01:15:07.657

Modified: 2024-11-21T06:17:15.620

Link: CVE-2021-38502

cve-icon Redhat

Severity : Important

Publid Date: 2021-10-06T00:00:00Z

Links: CVE-2021-38502 - Bugzilla

cve-icon OpenCVE Enrichment

No data.