Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqgq-4wpf-xfr8

Опубликовано: 22 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.

Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.

EPSS

Процентиль: 16%
0.00051
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.

EPSS

Процентиль: 16%
0.00051
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-347