CVE-2024-48460

An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.
Configurations

No configuration.

History

03 Feb 2025, 21:15

Type Values Removed Values Added
CWE CWE-295
Summary
  • (es) Un problema en Eugeny Tabby 1.0.213 permite a un atacante remoto obtener información confidencial a través del servidor y envía el nombre de usuario y la contraseña SSH incluso cuando falla la verificación de la clave del host.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

16 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-16 22:15

Updated : 2025-02-03 21:15


NVD link : CVE-2024-48460

Mitre link : CVE-2024-48460

CVE.ORG link : CVE-2024-48460


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation