2024-12-08 03:06:42 +00:00

158 lines
5.1 KiB
JSON

{
"id": "CVE-2010-3902",
"sourceIdentifier": "cve@mitre.org",
"published": "2010-10-14T05:58:42.927",
"lastModified": "2024-11-21T01:19:51.967",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output posted to the public openconnect-devel mailing list."
},
{
"lang": "es",
"value": "OpenConnect anterior v2.26 coloca el valor de la cookie WebVPN en la salida de depuraci\u00f3n,lo que puede permitir a atacantes remotos obtener informaci\u00f3n sensible por lectura de esta salida, como qued\u00f3 demotrados en la salida posteada en la lista p\u00fablica de correo openconnect-devel. \r\n\r\n"
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:infradead:openconnect:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.25",
"matchCriteriaId": "0726D7A0-1785-40E5-A0DF-83FB6DA75D77"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:infradead:openconnect:1.00:*:*:*:*:*:*:*",
"matchCriteriaId": "67DF6A41-F66A-4988-8852-08B0F8409185"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:infradead:openconnect:1.10:*:*:*:*:*:*:*",
"matchCriteriaId": "13B5B9C7-3D91-4A40-BEE2-F1BEF2857C4F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:infradead:openconnect:1.20:*:*:*:*:*:*:*",
"matchCriteriaId": "DFF4C32E-4053-4968-B2E7-C821908B3017"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:infradead:openconnect:1.30:*:*:*:*:*:*:*",
"matchCriteriaId": "92A36920-3A90-4369-A8F4-515C423BE938"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:infradead:openconnect:2.22:*:*:*:*:*:*:*",
"matchCriteriaId": "D3192A04-7811-4688-BF1E-4B6FA91D83D5"
}
]
}
]
}
],
"references": [
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051620.html",
"source": "cve@mitre.org"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051637.html",
"source": "cve@mitre.org"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051640.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/42381",
"source": "cve@mitre.org"
},
{
"url": "http://www.infradead.org/openconnect.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/44111",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3078",
"source": "cve@mitre.org"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051620.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051637.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051640.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42381",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.infradead.org/openconnect.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/44111",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3078",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}