Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwcq-rjr3-7rr9

Опубликовано: 05 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files.

GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files.

EPSS

Процентиль: 2%
0.00014
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-599

Связанные уязвимости

CVSS3: 6.8
nvd
3 месяца назад

GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files.

EPSS

Процентиль: 2%
0.00014
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-599