Описание
Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applications. Prior to version 3.118.12, it correctly blocks the file: URL scheme, which can be used by malicious actors to gain code execution on a victims computer, however fails to check other harmful schemes such as ftp:, smb:, etc. which can also be used. Successful exploitation of this vulnerability will enable an attacker to gain code execution on a victim's computer. Version 3.118.2 contains a patch for this issue.
Ссылки
- Product
- Product
- Patch
- ExploitVendor Advisory
- Exploit
- Product
- Product
- Patch
- ExploitVendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 3.118.12 (исключая)
cpe:2.3:a:tuta:tutanota:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 75%
0.00867
Низкий
9.3 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo
EPSS
Процентиль: 75%
0.00867
Низкий
9.3 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo