Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jg3f-p7fw-74wx

Опубликовано: 26 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 2.3
CVSS3: 4.3

Описание

The goTenna Pro ATAK Plugin does not encrypt the callsigns of its users. These callsigns reveal information about the users and can also be leveraged for other vulnerabilities.

The goTenna Pro ATAK Plugin does not encrypt the callsigns of its users. These callsigns reveal information about the users and can also be leveraged for other vulnerabilities.

EPSS

Процентиль: 6%
0.00025
Низкий

2.3 Low

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and previous versions of the plugin. Update to current plugin version which uses AES-256 encryption for callsigns in encrypted operation

EPSS

Процентиль: 6%
0.00025
Низкий

2.3 Low

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-319