Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x3x6-8w8x-2p8g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web site.

Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web site.

EPSS

Процентиль: 48%
0.00248
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web site.

EPSS

Процентиль: 48%
0.00248
Низкий