René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

107 lines
3.5 KiB
JSON

{
"id": "CVE-2018-18908",
"sourceIdentifier": "cve@mitre.org",
"published": "2019-01-20T20:29:00.460",
"lastModified": "2019-10-03T00:03:26.223",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The Sky Go Desktop application 1.0.19-1 through 1.0.23-1 for Windows performs several requests over cleartext HTTP. This makes the data submitted in these requests prone to Man in The Middle (MiTM) attacks, whereby an attacker would be able to obtain the data sent in these requests. Some of the requests contain potentially sensitive information that could be useful to an attacker, such as the victim's Sky username."
},
{
"lang": "es",
"value": "La aplicaci\u00f3n Sky Go Desktop, desde la versi\u00f3n 1.0.19-1 hasta la 1.0.23-1 para Windows, realiza varias peticiones sobre HTTP en texto claro. Esto hace que los datos introducidos en estas peticiones sean m\u00e1s propensos a ataques Man-in-the-Middle (MitM) en los que un atacante podr\u00eda obtener los datos enviados en las mismas. Algunas de las peticiones contienen informaci\u00f3n potencialmente sensible que podr\u00eda ser \u00fatil para un atacante, como puede ser el nombre de usuario de la v\u00edctima de Sky."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sky:sky_go:*:*:*:*:*:windows:*:*",
"versionStartIncluding": "1.0.19-1",
"versionEndIncluding": "1.0.23-1",
"matchCriteriaId": "A93C86F3-6BD2-48F4-BBD1-9517B26F6EAA"
}
]
}
]
}
],
"references": [
{
"url": "https://blog.sean-wright.com/sky/",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}