SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-6794

This could allow the exposure of stored password data outside of user expectations.

MEDIUM 6.5EPSS 1.02%

Does this matter?

Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.

Description

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Thunderbird < 68.5.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
1.02% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-312, CWE-459, CWE-522
Affected
mozilla/thunderbird · canonical/ubuntu linux
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.