Описание
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
Ссылки
- Not ApplicableURL Repurposed
- Not ApplicableURL Repurposed
- Third Party Advisory
- Not ApplicableURL Repurposed
- Not ApplicableURL Repurposed
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:mealie:mealie:0.5.5:*:*:*:*:*:*:*
cpe:2.3:a:mealie:mealie:1.0.0:beta3:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.0027
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-613
Связанные уязвимости
CVSS3: 5.9
github
больше 3 лет назад
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
EPSS
Процентиль: 50%
0.0027
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-613