Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1000072

Опубликовано: 13 мар. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's password protected secret GPG key file and other important configuration files.. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in Beta: 0.9.8-BETA1, Stable: 0.9.7.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:iredmail:iredmail:*:*:*:*:*:*:*:*
Версия до 0.9.6 (включая)

EPSS

Процентиль: 51%
0.00281
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's password protected secret GPG key file and other important configuration files.. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in Beta: 0.9.8-BETA1, Stable: 0.9.7.

EPSS

Процентиль: 51%
0.00281
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-732