Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2h9h-wfvh-5r96

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

EPSS

Процентиль: 59%
0.00383
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

CVSS3: 7.5
nvd
больше 5 лет назад

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

CVSS3: 7.5
debian
больше 5 лет назад

Alpine before 2.23 silently proceeds to use an insecure connection aft ...

suse-cvrf
почти 5 лет назад

Security update for alpine

EPSS

Процентиль: 59%
0.00383
Низкий

7.5 High

CVSS3

Дефекты

CWE-200