Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwrm-86h9-fvj6

Опубликовано: 16 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to intercept, read, or modify network communications to and from the affected service. This issue affects: Palantir Palantir Gotham Chat IRC helper versions prior to 30221005.210011.9242.

Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to intercept, read, or modify network communications to and from the affected service. This issue affects: Palantir Palantir Gotham Chat IRC helper versions prior to 30221005.210011.9242.

EPSS

Процентиль: 28%
0.00102
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.7
nvd
почти 3 года назад

Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to intercept, read, or modify network communications to and from the affected service. This issue affects: Palantir Palantir Gotham Chat IRC helper versions prior to 30221005.210011.9242.

EPSS

Процентиль: 28%
0.00102
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-295