Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8qg-j9fp-hrjf

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

phpMyAdmin Improper Input Validation

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

Пакеты

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 4.5, < 4.5.5.1

4.5.5.1

EPSS

Процентиль: 56%
0.00337
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 9 лет назад

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

CVSS3: 6.8
nvd
больше 9 лет назад

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

CVSS3: 6.8
debian
больше 9 лет назад

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5 ...

EPSS

Процентиль: 56%
0.00337
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-20