Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qfq-632q-hr28

Опубликовано: 10 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, a man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected App.

TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, a man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected App.

EPSS

Процентиль: 37%
0.00159
Низкий

3.7 Low

CVSS3

Дефекты

CWE-419

Связанные уязвимости

CVSS3: 3.7
nvd
больше 1 года назад

TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, a man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected App.

EPSS

Процентиль: 37%
0.00159
Низкий

3.7 Low

CVSS3

Дефекты

CWE-419