Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxfx-h38m-cr9x

Опубликовано: 26 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions.

This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions.

This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.

EPSS

Процентиль: 5%
0.00022
Низкий

8 High

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 8
nvd
8 месяцев назад

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.

EPSS

Процентиль: 5%
0.00022
Низкий

8 High

CVSS3

Дефекты

CWE-266