Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g3x9-82h5-gj65

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent through a proxy server.

Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent through a proxy server.

EPSS

Процентиль: 12%
0.00041
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 16 лет назад

Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent through a proxy server.

EPSS

Процентиль: 12%
0.00041
Низкий

Дефекты

CWE-287