In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
2024-01-23T14:15:38.730
2025-06-07T21:15:21.370
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 122.0 | Yes |
Application | mozilla | firefox_esr | < 115.7 | Yes |
Application | mozilla | thunderbird | < 115.7 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |