Описание
Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. API_URLS is utilizing HTTP instead of HTTPS for communication that can lead to issues like Eavesdropping, Data Tampering, Unauthorized Data Access & MITM Attacks. This issue has been addressed in release version 0.21 by using https rather than http connections. All users are advised to upgrade. There is no known workarounds for this vulnerability.
Ссылки
EPSS
Процентиль: 7%
0.00027
Низкий
6.3 Medium
CVSS3
Дефекты
CWE-311
Связанные уязвимости
CVSS3: 3.8
github
больше 1 года назад
[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`
EPSS
Процентиль: 7%
0.00027
Низкий
6.3 Medium
CVSS3
Дефекты
CWE-311