Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-34p7-67p6-m2pf

Опубликовано: 12 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option.

Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.

The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option.

Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.

EPSS

Процентиль: 44%
0.00218
Низкий

7.5 High

CVSS3

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 года назад

The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.

EPSS

Процентиль: 44%
0.00218
Низкий

7.5 High

CVSS3

Дефекты

CWE-665