Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gvvc-pv9r-rg5q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information.

The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information.

EPSS

Процентиль: 73%
0.0078
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information. NOTE: The network team of Tor claims this is an intended behavior and not a vulnerability

CVSS3: 5.3
nvd
около 6 лет назад

The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information. NOTE: The network team of Tor claims this is an intended behavior and not a vulnerability

CVSS3: 5.3
debian
около 6 лет назад

The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not ...

EPSS

Процентиль: 73%
0.0078
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200