6.4
CVSSv2

CVE-2019-9149

Published: 09/07/2019 Updated: 18/04/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Mailvelope before 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelope, assuming the private key password is cached. A second vulnerability allows an malicious user to decrypt an arbitrary message when the GnuPG backend is used in Mailvelope.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mailvelope mailvelope