Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59pp-rvhc-93rh

Опубликовано: 19 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

EPSS

Процентиль: 67%
0.00536
Низкий

10 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 10
nvd
около 1 года назад

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.

EPSS

Процентиль: 67%
0.00536
Низкий

10 Critical

CVSS3

Дефекты

CWE-863