Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-855x-qr5w-6pwv

Опубликовано: 23 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.

The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.

EPSS

Процентиль: 44%
0.00212
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-319
CWE-838

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.

EPSS

Процентиль: 44%
0.00212
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-319
CWE-838