Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3pc4-pj89-2j67

Опубликовано: 10 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.

EPSS

Процентиль: 53%
0.00307
Низкий

8.8 High

CVSS3

Дефекты

CWE-807

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.

EPSS

Процентиль: 53%
0.00307
Низкий

8.8 High

CVSS3

Дефекты

CWE-807