Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgp3-jrf2-crj2

Опубликовано: 28 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6

Описание

Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs.

Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs.

EPSS

Процентиль: 1%
0.00008
Низкий

6 Medium

CVSS4

Дефекты

CWE-649

Связанные уязвимости

nvd
11 дней назад

Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs.

EPSS

Процентиль: 1%
0.00008
Низкий

6 Medium

CVSS4

Дефекты

CWE-649