Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2mc-pw6q-5pv7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.

EPSS

Процентиль: 72%
0.01469
Низкий

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.

CVSS3: 7.5
nvd
больше 5 лет назад

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.

CVSS3: 7.5
debian
больше 5 лет назад

libgrss through 0.7.0 fails to perform TLS certificate verification wh ...

CVSS3: 7.5
fstec
почти 10 лет назад

Уязвимость библиотеки управления потоками RSS/Atom/Pie LibGRSS, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 72%
0.01469
Низкий

Дефекты

CWE-295