CVE Vulnerabilities

CVE-2025-3932

Authentication Bypass Using an Alternate Path or Channel

Published: May 14, 2025 | Modified: Jun 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Thunderbird Mozilla * 128.10.1 (excluding)
Thunderbird Mozilla 129.0 (including) 138.0.1 (excluding)
Red Hat Enterprise Linux 10 RedHat thunderbird-0:128.10.1-1.el10_0 *
Red Hat Enterprise Linux 8 RedHat thunderbird-0:128.11.0-1.el8_10 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat thunderbird-0:128.10.1-1.el8_2 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat thunderbird-0:128.10.1-1.el8_4 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat thunderbird-0:128.10.1-1.el8_6 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat thunderbird-0:128.10.1-1.el8_6 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat thunderbird-0:128.10.1-1.el8_6 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat thunderbird-0:128.10.1-1.el8_8 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat thunderbird-0:128.10.1-1.el8_8 *
Red Hat Enterprise Linux 9 RedHat thunderbird-0:128.10.1-1.el9_6 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat thunderbird-0:128.10.1-1.el9_0 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat thunderbird-0:128.10.1-1.el9_2 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat thunderbird-0:128.10.1-1.el9_4 *
Thunderbird Ubuntu focal *

Potential Mitigations

References