5
CVSSv2

CVE-2017-1000001

Published: 17/07/2017 Updated: 26/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedmsg

Vendor Advisories

Debian Bug report logs - #868508 fedmsg: CVE-2017-1000001 Package: src:fedmsg; Maintainer for src:fedmsg is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 16 Jul 2017 09:03:01 UTC Severity: grave Tags: security, upstream Foun ...