SB2021011012 - Information disclosure in thunderbird (Alpine package)
Published: January 10, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2020-35111)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the proxy.onRequest API does not use proxy when viewing source code of the web application. A remote attacker, who controls the web server can obtain user's real IP address, if the user decides to view the web application source code while behind a proxy server.
Remediation
Install update from vendor's website.