Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-41124

Опубликовано: 19 июл. 2024
Источник: nvd
CVSS3: 6.3
EPSS Низкий

Описание

Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. API_URLS is utilizing HTTP instead of HTTPS for communication that can lead to issues like Eavesdropping, Data Tampering, Unauthorized Data Access & MITM Attacks. This issue has been addressed in release version 0.21 by using https rather than http connections. All users are advised to upgrade. There is no known workarounds for this vulnerability.

EPSS

Процентиль: 7%
0.00027
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 3.8
github
больше 1 года назад

[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`

EPSS

Процентиль: 7%
0.00027
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-311