7.5

CVE-2018-20954

The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MailpileMailpile Version0.5.0
MailpileMailpile Version0.5.1
MailpileMailpile Version0.5.2
MailpileMailpile Version1.0.0 Updaterc0
MailpileMailpile Version1.0.0 Updaterc1
MailpileMailpile Version1.0.0 Updaterc2
MailpileMailpile Version1.0.0 Updaterc3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.409
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.