An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
2022-12-22T20:15:29.277
2025-04-15T19:15:58.717
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 101 | Yes |
Application | mozilla | firefox_esr | < 91.10 | Yes |
Application | mozilla | thunderbird | < 91.10 | Yes |