Related Vulnerabilities: CVE-2021-23998  

A security issue has been found in Firefox before version 88 and Thunderbird before version 78.10. Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page.

Severity Medium

Remote Yes

Type Content spoofing

Description

A security issue has been found in Firefox before version 88 and Thunderbird before version 78.10. Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page.

AVG-1836 thunderbird 78.9.1-3 High Vulnerable

AVG-1834 firefox 87.0-2 88.0-1 High Testing

https://www.mozilla.org/en-US/security/advisories/mfsa2021-16/#CVE-2021-23998
https://www.mozilla.org/en-US/security/advisories/mfsa2021-14/#CVE-2021-23998
https://bugzilla.mozilla.org/show_bug.cgi?id=1667456