Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20436

Опубликовано: 24 дек. 2018
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that chat message is sent. There are also GET requests to other URLs on the same web server. This also affects one or more other Telegram products, such as Telegram Web-version 0.7.0. In addition, it can be interpreted as an SSRF issue. NOTE: a third party has reported that potentially unwanted behavior is caused by misconfiguration of the "Secret chats > Preview links" setting

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:telegram:telegram:4.9.1:*:*:*:*:android:*:*
cpe:2.3:a:telegram:web:0.7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00482
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

** DISPUTED ** The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that chat message is sent. There are also GET requests to other URLs on the same web server. This also affects one or more other Telegram products, such as Telegram Web-version 0.7.0. In addition, it can be interpreted as an SSRF issue. NOTE: a third party has reported that potentially unwanted behavior is caused by misconfiguration of the "Secret chats > Preview links" setting.

EPSS

Процентиль: 65%
0.00482
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-918