Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c686-g9ff-6f7m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.

The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.

EPSS

Процентиль: 36%
0.00151
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 5.3
nvd
около 6 лет назад

The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.

EPSS

Процентиль: 36%
0.00151
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1188