Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-19443

Опубликовано: 22 нояб. 2018
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the header the current session of the user. This session could then be stolen by a man-in-the-middle.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tryton:tryton:5.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00196
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 7 лет назад

The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the header the current session of the user. This session could then be stolen by a man-in-the-middle.

CVSS3: 5.9
debian
около 7 лет назад

The client in Tryton 5.x before 5.0.1 tries to make a connection to th ...

suse-cvrf
около 7 лет назад

Security update for tryton

suse-cvrf
около 7 лет назад

Security update for tryton

CVSS3: 5.9
github
около 7 лет назад

Session Fixation in Tryton

EPSS

Процентиль: 42%
0.00196
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-384