CVE-2021-38502 - log back

CVE-2021-38502 edited at 12 Oct 2021 14:47:38
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Type
- Unknown
+ Man-in-the-middle
Description
+ Thunderbird before version 91.2 ignored the configuration to require STARTTLS security for an SMTP connection. A man-in-the-middle (MITM) could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too.
References
+ https://www.mozilla.org/security/advisories/mfsa2021-47/
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1733366
CVE-2021-38502 created at 12 Oct 2021 14:41:00