Описание
fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates.
Ссылки
- Mailing ListPatchThird Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingPatchThird Party Advisory
- Mailing ListPatchThird Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:a:fedoraproject:spin-kickstarts:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:atomic:-:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00473
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
CVSS3: 5.9
github
больше 3 лет назад
fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates.
EPSS
Процентиль: 64%
0.00473
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-264