Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6qcx-92g2-v777

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.

The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.

EPSS

Процентиль: 45%
0.00222
Низкий

Связанные уязвимости

nvd
больше 14 лет назад

The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.

EPSS

Процентиль: 45%
0.00222
Низкий