Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wv2-923f-jxwr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.5

Описание

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

EPSS

Процентиль: 66%
0.00523
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
ubuntu
больше 8 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

CVSS3: 4.5
nvd
больше 8 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

CVSS3: 4.5
debian
больше 8 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote ...

suse-cvrf
больше 8 лет назад

Security update for gajim

EPSS

Процентиль: 66%
0.00523
Низкий

4.5 Medium

CVSS3