Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without any warning to the user, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted X.509 server certificate.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade epiphany-browser | Jul 30, 2024 | Oct 14, 2010 |
| Suse | — | Upgrade epiphany-develUpgrade epiphany-langUpgrade webkit-jscUpgrade libwebkit-langUpgrade libwebkit-1_0-2Upgrade libwebkit-develUpgrade epiphany-docUpgrade libwebkit-1_0-2-32bitUpgrade epiphanyUpgrade epiphany-branding-upstream | Feb 17, 2015 | Oct 14, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub