CVE-2018-17215
Summary
| CVE | CVE-2018-17215 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-26 21:29:00 UTC |
| Updated | 2024-02-01 19:55:00 UTC |
| Description | An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and presents an error if the certificate is not valid. Unfortunately, the associated HTTPS request data is sent anyway. Only the response is not displayed. Thus, all contained information of the HTTPS request is disclosed to a man-in-the-middle attacker (for example, user credentials). |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Getpostman | Postman | All | All | All | All |
| Application | Postman | Postman | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bugtraq: [SYSS-2018-016] Postman - Improper Certificate Validation | BUGTRAQ | seclists.org | Exploit, Mailing List, Third Party Advisory |
| www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-016.txt | MISC | www.syss.de | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.