CVE-2021-38497 log

Source
Severity Medium
Remote Yes
Type Content spoofing
Description
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks.
Group Package Affected Fixed Severity Status Ticket
AVG-2459 thunderbird 91.1.2-1 91.2.0-1 High Fixed
AVG-2443 firefox 92.0.1-1 93.0-1 High Fixed
References
https://www.mozilla.org/security/advisories/mfsa2021-43/
https://www.mozilla.org/security/advisories/mfsa2021-47/
https://bugzilla.mozilla.org/show_bug.cgi?id=1726621