Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1000014

Опубликовано: 04 фев. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via Victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 3.8.0.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:*
Версия от 3.7.0 (включая) до 3.7.5 (включая)

EPSS

Процентиль: 67%
0.00548
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.8
debian
около 7 лет назад

Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracl ...

CVSS3: 8.8
github
больше 3 лет назад

Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via Victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 3.8.0.

EPSS

Процентиль: 67%
0.00548
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo