Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6fr7-2fr2-7jh9

Опубликовано: 01 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS.

In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS.

EPSS

Процентиль: 39%
0.00173
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

EPSS

Процентиль: 39%
0.00173
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-311