Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x927-rp8j-62cg

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.

putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.

EPSS

Процентиль: 54%
0.00309
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.

EPSS

Процентиль: 54%
0.00309
Низкий