Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 141
A vulnerability exists in Mozilla Firefox and Thunderbird due to improper handling of URLs in Content Security Policy (CSP) reports. Specifically, the 'username:password' portion of URLs was not adequately removed, potentially leading to the unintentional disclosure of HTTP Basic Authentication credentials. This issue affects multiple versions of Firefox and Thunderbird, including Firefox prior to 141, Firefox ESR prior to 128.13 and 140.1, as well as Thunderbird prior to 141, 128.13 and 140.1.
Exploitation of this vulnerability could result in the leakage of HTTP Basic Authentication credentials.
Users can upgrade to Firefox 141, Firefox ESR 128.13 or 140.1, Thunderbird 141, or Thunderbird ESR 128.13 or 140.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.