Impact
A flaw was found in the Networking: HTTP component that allows the disclosure of unexpected data. The vulnerability can cause an attacker to obtain information that the client application should not reveal. This weakness is reflected by the common weakness identifiers CWE‑201 and CWE‑200.
Affected Systems
Mozilla’s Firefox browser versions earlier than 156 (including all ESR releases prior to 153.3) and Thunderbird versions earlier than 156 (including all ESR releases prior to 153.3) are affected. Versions 156 and newer for Firefox, ESR 153.3 and newer for Firefox ESR, and 156 and newer for Thunderbird, ESR 153.3 and newer for Thunderbird are not impacted. Users should verify that their installed Firefox and Thunderbird versions are at or above these fixed releases.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact. The EPSS score of < 1% and the absence from CISA’s KEV catalog suggest that the vulnerability is not currently widely exploited or nationally significant. However, because the flaw permits disclosure of potentially sensitive data, the risk to confidentiality is real. The attack vector is inferred as remote; an adversary could trigger the disclosure by sending crafted HTTP traffic to the interface.
OpenCVE Enrichment