Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-48306

Опубликовано: 16 фев. 2023
Источник: nvd
CVSS3: 5.7
CVSS3: 6.8
EPSS Низкий

Описание

Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to intercept, read, or modify network communications to and from the affected service. This issue affects: Palantir Palantir Gotham Chat IRC helper versions prior to 30221005.210011.9242.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:palantir:gotham_chat_irc:*:*:*:*:*:palantir:*:*
Версия до 30221005.210011.9242 (исключая)

EPSS

Процентиль: 29%
0.00102
Низкий

5.7 Medium

CVSS3

6.8 Medium

CVSS3

Дефекты

CWE-297
CWE-295

Связанные уязвимости

CVSS3: 6.8
github
почти 3 года назад

Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to intercept, read, or modify network communications to and from the affected service. This issue affects: Palantir Palantir Gotham Chat IRC helper versions prior to 30221005.210011.9242.

EPSS

Процентиль: 29%
0.00102
Низкий

5.7 Medium

CVSS3

6.8 Medium

CVSS3

Дефекты

CWE-297
CWE-295