Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-9149

Опубликовано: 09 июл. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 6.4
EPSS Низкий

Описание

Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelope, assuming the private key password is cached. A second vulnerability allows an attacker to decrypt an arbitrary message when the GnuPG backend is used in Mailvelope.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mailvelope:mailvelope:*:*:*:*:*:*:*:*
Версия до 3.3.0 (исключая)

EPSS

Процентиль: 30%
0.00114
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelope, assuming the private key password is cached. A second vulnerability allows an attacker to decrypt an arbitrary message when the GnuPG backend is used in Mailvelope.

EPSS

Процентиль: 30%
0.00114
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-347