Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade libgoa-1_0-0Upgrade typelib-1_0-Goa-1_0Upgrade gnome-online-accounts-develUpgrade gnome-online-accounts-langUpgrade libgoa-backend-1_0-1Upgrade libgoa-1_0-0-32bitUpgrade gnome-online-accounts | Aug 9, 2024 | Apr 2, 2013 |
| Ubuntu | — | Upgrade libgoa-1.0-0Upgrade gnome-online-accounts | Nov 8, 2024 | Apr 2, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub