Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-33516

Опубликовано: 24 мая 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8
CVSS3: 8.1

Описание

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

released

1.2.4-1ubuntu1
esm-apps/bionic

needs-triage

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

1.2.3-0ubuntu0.20.04.2
focal

released

1.2.3-0ubuntu0.20.04.2
groovy

released

1.2.4-1ubuntu0.20.10.1
hirsute

released

1.2.4-1ubuntu0.21.04.1
impish

released

1.2.4-1ubuntu1

Показывать по

EPSS

Процентиль: 65%
0.00494
Низкий

5.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
redhat
около 4 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

CVSS3: 8.1
nvd
около 4 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

CVSS3: 8.1
debian
около 4 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x befo ...

suse-cvrf
почти 4 года назад

Security update for gupnp

suse-cvrf
почти 4 года назад

Security update for gupnp

EPSS

Процентиль: 65%
0.00494
Низкий

5.8 Medium

CVSS2

8.1 High

CVSS3

Уязвимость CVE-2021-33516