The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1971719 | permissions required |
https://www.mozilla.org/security/advisories/mfsa2025-56/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2025-58/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2025-59/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2025-61/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2025-62/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2025-63/ | vendor advisory |