Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.
History

Sat, 23 Nov 2024 02:30:00 +0000

Type Values Removed Values Added
Title thunderbird: Potential disclosure of plaintext in OpenPGP encrypted message
Weaknesses CWE-200
References
Metrics threat_severity

None

threat_severity

Important


Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Tue, 19 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla thunderbird
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla
Mozilla thunderbird
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 13 Nov 2024 14:00:00 +0000

Type Values Removed Values Added
Description Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2024-11-13T13:42:50.499Z

Updated: 2024-11-20T11:02:41.682Z

Reserved: 2024-11-12T18:40:18.348Z

Link: CVE-2024-11159

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-11-13T14:15:15.330

Modified: 2024-11-21T08:49:23.780

Link: CVE-2024-11159

cve-icon Redhat

Severity : Important

Publid Date: 2024-11-13T13:42:50Z

Links: CVE-2024-11159 - Bugzilla