CVE-2024-41253 - CERT CVE
ID CVE-2024-41253
Sažetak goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.
Reference
CVSS
Base: 7.1
Impact: 5.9
Exploitability:1.2
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 01-08-2024 - 13:58
Objavljeno 31-07-2024 - 21:15