Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fh7-mv59-556w

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

EPSS

Процентиль: 34%
0.00135
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.9
nvd
почти 8 лет назад

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

CVSS3: 5.9
debian
почти 8 лет назад

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17 ...

EPSS

Процентиль: 34%
0.00135
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-295