Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
References
Link | Resource |
---|---|
https://mail.gnome.org/archives/shotwell-list/2017-January/msg00048.html | Mailing List Vendor Advisory |
https://mail.gnome.org/archives/shotwell-list/2017-January/msg00048.html | Mailing List Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://mail.gnome.org/archives/shotwell-list/2017-January/msg00048.html - Mailing List, Vendor Advisory |
Information
Published : 2017-07-17 13:18
Updated : 2024-11-21 03:03
NVD link : CVE-2017-1000024
Mitre link : CVE-2017-1000024
CVE.ORG link : CVE-2017-1000024
JSON object : View
Products Affected
gnome
- shotwell
CWE
CWE-319
Cleartext Transmission of Sensitive Information