Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
References
Link | Resource |
---|---|
https://mail.gnome.org/archives/shotwell-list/2017-January/msg00048.html | Mailing List Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-07-17 06:18
Updated : 2019-10-02 17:03
NVD link : CVE-2017-1000024
Mitre link : CVE-2017-1000024
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
gnome
- shotwell