CVE-2017-1000025Sensitive Information Exposure in Epiphany

Severity
7.5HIGHNVD
EPSS
0.5%
top 34.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 17
Latest updateMay 17

Description

GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDgnome/epiphany31 versions+30

🔴Vulnerability Details

3
GHSA
GHSA-3gg9-xvf5-p5wm: GNOME Web (Epiphany) 32022-05-17
OSV
CVE-2017-1000025: GNOME Web (Epiphany) 32017-07-17
CVEList
CVE-2017-1000025: GNOME Web (Epiphany) 32017-07-13

📋Vendor Advisories

1
Debian
CVE-2017-1000025: epiphany-browser - GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7,...2017
CVE-2017-1000025 — Sensitive Information Exposure | cvebase