Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65w5-qrhr-h35g

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.

Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.

EPSS

Процентиль: 72%
0.00708
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 17 лет назад

Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.

EPSS

Процентиль: 72%
0.00708
Низкий

Дефекты

CWE-200