Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6v84-2ccf-99qx

Опубликовано: 27 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).

An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).

EPSS

Процентиль: 20%
0.00064
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 5.5
nvd
почти 4 года назад

An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).

EPSS

Процентиль: 20%
0.00064
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-276