CVE-2021-38505
Summary
| CVE | CVE-2021-38505 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-08 22:15:00 UTC |
| Updated | 2021-12-10 17:02:00 UTC |
| Description | Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296066 Oracle Solaris 11.4 Support Repository Update (SRU) 40.107.3 Missing (CPUOCT2021)
- 376014 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2021-49)
- 376015 Mozilla Firefox Multiple Vulnerabilities (MFSA2021-48)
- 376038 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-50)
- 502070 Alpine Linux Security Update for firefox-esr
- 502082 Alpine Linux Security Update for firefox
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 503853 Alpine Linux Security Update for firefox
- 506260 Alpine Linux Security Update for thunderbird
- 751360 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3651-1)
- 751371 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:3745-1)
- 751387 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3721-1)
- 751542 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:4150-1)
- 751566 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1635-1)