Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c5p-g26h-xx2f

Опубликовано: 10 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE.

Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange. This issue affects Apache NimBLE: through <= 1.8.0.

Users are recommended to upgrade to version 1.9.0, which fixes the issue.

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE.

Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange. This issue affects Apache NimBLE: through <= 1.8.0.

Users are recommended to upgrade to version 1.9.0, which fixes the issue.

EPSS

Процентиль: 9%
0.00032
Низкий

7.5 High

CVSS3

Дефекты

CWE-5

Связанные уязвимости

CVSS3: 7.5
nvd
29 дней назад

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange. This issue affects Apache NimBLE: through <= 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issue.

EPSS

Процентиль: 9%
0.00032
Низкий

7.5 High

CVSS3

Дефекты

CWE-5