Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hp56-xvf4-g6wr

Опубликовано: 20 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Cros secrets may be disclosed to untrusted relay

An issue was discovered in Croc before 9.6.16. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of composing a room name.

Пакеты

Наименование

github.com/schollz/croc/v9

go
Затронутые версииВерсия исправления

< 9.6.16

9.6.16

EPSS

Процентиль: 33%
0.00128
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of composing a room name.

CVSS3: 5.3
debian
больше 2 лет назад

An issue was discovered in Croc through 9.6.5. When a custom shared se ...

EPSS

Процентиль: 33%
0.00128
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200