Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq64-rh4x-r9x6

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Investigation Tool (aka gov.ca.post.lp.itool) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

The Investigation Tool (aka gov.ca.post.lp.itool) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS

Процентиль: 31%
0.00115
Низкий

Связанные уязвимости

nvd
больше 11 лет назад

The Investigation Tool (aka gov.ca.post.lp.itool) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS

Процентиль: 31%
0.00115
Низкий