Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5x6q-ffwj-8vcf

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

attic has improper verification of unencrypted backups

attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted repository to obtain potentially sensitive information by changing the manifest type byte of the repository to "unencrypted / without key file".

Пакеты

Наименование

attic

pip
Затронутые версииВерсия исправления

< 0.15

0.15

EPSS

Процентиль: 75%
0.00858
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted repository to obtain potentially sensitive information by changing the manifest type byte of the repository to "unencrypted / without key file".

CVSS3: 6.5
nvd
больше 8 лет назад

attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted repository to obtain potentially sensitive information by changing the manifest type byte of the repository to "unencrypted / without key file".

CVSS3: 6.5
debian
больше 8 лет назад

attic before 0.15 does not confirm unencrypted backups with the user, ...

EPSS

Процентиль: 75%
0.00858
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3