Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vqgc-h3q6-423f

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding.

BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding.

EPSS

Процентиль: 31%
0.0012
Низкий

Дефекты

CWE-352

Связанные уязвимости

nvd
около 12 лет назад

BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding.

EPSS

Процентиль: 31%
0.0012
Низкий

Дефекты

CWE-352