Impact
The vulnerability exists in the Networking: HTTP component of Mozilla Firefox and Thunderbird. It allows an attacker to disclose information that is otherwise intended to be confidential, potentially exposing sensitive data handled by the HTTP stack.
Affected Systems
All installations of Firefox older than version 155, including the ESR branch before 153.2, are affected. The same applies to Thunderbird installations before 155 and the ESR branch before 153.2.
Risk and Exploitability
The EPSS score is < 1% and the issue is not listed in CISA’s KEV catalog, indicating that no public exploit has been documented. The CVSS score is 7.5. Given the lack of public exploitation evidence, the risk can be considered low to moderate. The likely attack vector involves untrusted inputs to the Networking: HTTP component, based on the nature of the vulnerability; however, this is inferred from the description and not explicitly stated in the CVE data.
OpenCVE Enrichment