Описание
An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needs-triage |
devel | released | 1.2.4-1ubuntu1 |
esm-apps/bionic | needs-triage | |
esm-apps/xenial | needs-triage | |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | not-affected | 1.2.3-0ubuntu0.20.04.2 |
focal | released | 1.2.3-0ubuntu0.20.04.2 |
groovy | released | 1.2.4-1ubuntu0.20.10.1 |
hirsute | released | 1.2.4-1ubuntu0.21.04.1 |
impish | released | 1.2.4-1ubuntu1 |
Показывать по
EPSS
5.8 Medium
CVSS2
8.1 High
CVSS3
Связанные уязвимости
An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.
An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.
An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x befo ...
EPSS
5.8 Medium
CVSS2
8.1 High
CVSS3