Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92ch-fw3f-gxmq

Опубликовано: 15 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An information disclosure vulnerability in the?faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could use these credentials to impersonate PTR/TRAP to these services. All versions prior to 5.10.0 are affected. 

An information disclosure vulnerability in the?faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could use these credentials to impersonate PTR/TRAP to these services. All versions prior to 5.10.0 are affected. 

EPSS

Процентиль: 18%
0.00056
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-200
CWE-668

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could use these credentials to impersonate PTR/TRAP to these services. All versions prior to 5.10.0 are affected. 

EPSS

Процентиль: 18%
0.00056
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-200
CWE-668