Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-67rq-xjmx-ww89

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network traffic and gain access to the authorization credentials used to make the invitation requests.

Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network traffic and gain access to the authorization credentials used to make the invitation requests.

EPSS

Процентиль: 48%
0.0025
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-300
CWE-319

Связанные уязвимости

CVSS3: 9.8
nvd
почти 7 лет назад

Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network traffic and gain access to the authorization credentials used to make the invitation requests.

EPSS

Процентиль: 48%
0.0025
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-300
CWE-319