Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrwh-wc9j-x9cj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS

Процентиль: 59%
0.00384
Низкий

Связанные уязвимости

CVSS3: 7.4
nvd
около 6 лет назад

Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS

Процентиль: 59%
0.00384
Низкий