{"api_version":"1","generated_at":"2026-07-23T08:11:53+00:00","cve":"CVE-2013-1799","urls":{"html":"https://cve.report/CVE-2013-1799","api":"https://cve.report/api/cve/CVE-2013-1799.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-1799","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-1799"},"summary":{"title":"CVE-2013-1799","description":"Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.  NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.","state":"PUBLISHED","assigner":"redhat","published_at":"2013-04-02 03:23:26","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.html","name":"https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"GNOME Online Accounts 3.7.91 released","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8","name":"https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Guard against invalid SSL certificates (9cf4bc0c) · Commits · GNOME / gnome-online-accounts · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.html","name":"http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2013:0301-1: moderate: gnome-online-accounts: enable ssl cer","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/51976","name":"http://secunia.com/advisories/51976","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA51976 - GNOME Online Accounts SSL Certificate Verification Security Issue - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.gnome.org/show_bug.cgi?id=695106","name":"https://bugzilla.gnome.org/show_bug.cgi?id=695106","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 695106 – CVE-2013-1799: Do not send the credentials before notifying the user of an invalid SSL certificate","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://ubuntu.com/usn/usn-1779-1","name":"http://ubuntu.com/usn/usn-1779-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-1779-1: GNOME Online Accounts vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.gnome.org/show_bug.cgi?id=693214","name":"https://bugzilla.gnome.org/show_bug.cgi?id=693214","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 693214 – CVE-2013-0240: fails to verify SSL certificates when creating accounts","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html","name":"https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"GNOME Online Accounts 3.6.3 released","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/52791","name":"http://secunia.com/advisories/52791","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA52791 - Ubuntu update for gnome-online-accounts - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-1799","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1799","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"11.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"12.04","cpe7":"-","cpe8":"lts","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"12.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"gnome_online_accounts","cpe6":"3.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"gnome_online_accounts","cpe6":"3.6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"gnome_online_accounts","cpe6":"3.6.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"gnome_online_accounts","cpe6":"3.7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"gnome_online_accounts","cpe6":"3.7.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"gnome_online_accounts","cpe6":"3.7.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"gnome_online_accounts","cpe6":"3.7.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1799","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"gnome_online_accounts","cpe6":"3.7.90","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T15:13:33.277Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[gnome-announce-list] 20130305 GNOME Online Accounts 3.7.91 released","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8"},{"name":"51976","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51976"},{"name":"[gnome-announce-list] 20130304 GNOME Online Accounts 3.6.3 released","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.gnome.org/show_bug.cgi?id=695106"},{"name":"USN-1779-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://ubuntu.com/usn/usn-1779-1"},{"name":"52791","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/52791"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.gnome.org/show_bug.cgi?id=693214"},{"name":"openSUSE-SU-2013:0301","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.  NOTE: this issue exists because of an incomplete fix for CVE-2013-0240."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2013-03-28T17:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"[gnome-announce-list] 20130305 GNOME Online Accounts 3.7.91 released","tags":["mailing-list","x_refsource_MLIST"],"url":"https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8"},{"name":"51976","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51976"},{"name":"[gnome-announce-list] 20130304 GNOME Online Accounts 3.6.3 released","tags":["mailing-list","x_refsource_MLIST"],"url":"https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.gnome.org/show_bug.cgi?id=695106"},{"name":"USN-1779-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://ubuntu.com/usn/usn-1779-1"},{"name":"52791","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/52791"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.gnome.org/show_bug.cgi?id=693214"},{"name":"openSUSE-SU-2013:0301","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.html"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2013-1799","datePublished":"2013-03-28T17:00:00.000Z","dateReserved":"2013-02-19T00:00:00.000Z","dateUpdated":"2024-08-06T15:13:33.277Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-04-02 03:23:26","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gnome:gnome_online_accounts:3.6.0:*:*:*:*:*:*:*","matchCriteriaId":"5971CF55-885F-4CED-8491-65DBCE785B6C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gnome:gnome_online_accounts:3.6.1:*:*:*:*:*:*:*","matchCriteriaId":"B74804B4-06B7-4EBA-878B-8B000CFAF436"},{"vulnerable":true,"criteria":"cpe:2.3:a:gnome:gnome_online_accounts:3.6.2:*:*:*:*:*:*:*","matchCriteriaId":"28FBF215-4BE8-445C-B90C-7AA26DF842E7"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gnome:gnome_online_accounts:3.7.1:*:*:*:*:*:*:*","matchCriteriaId":"293EDD49-EECF-41B7-A57D-D7DDF958B31D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gnome:gnome_online_accounts:3.7.2:*:*:*:*:*:*:*","matchCriteriaId":"D28A7DA8-54A0-45AB-845C-74163353DAC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gnome:gnome_online_accounts:3.7.3:*:*:*:*:*:*:*","matchCriteriaId":"3427636E-5B7E-447E-8B94-34C3930E0E05"},{"vulnerable":true,"criteria":"cpe:2.3:a:gnome:gnome_online_accounts:3.7.4:*:*:*:*:*:*:*","matchCriteriaId":"F2759201-0DBD-48A2-B8C1-7F145AADF747"},{"vulnerable":true,"criteria":"cpe:2.3:a:gnome:gnome_online_accounts:3.7.90:*:*:*:*:*:*:*","matchCriteriaId":"1345D6B2-AA1C-411F-91EC-35A807D0A1D7"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*","matchCriteriaId":"E4174F4F-149E-41A6-BBCC-D01114C05F38"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*","matchCriteriaId":"F5D324C4-97C7-49D3-A809-9EAD4B690C69"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*","matchCriteriaId":"E2076871-2E80-4605-A470-A41C1A8EC7EE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"1799","Ordinal":"1","Title":"CVE-2013-1799","CVE":"CVE-2013-1799","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"1799","Ordinal":"1","NoteData":"Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.  NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.","Type":"Description","Title":"CVE-2013-1799"},{"CveYear":"2013","CveId":"1799","Ordinal":"2","NoteData":"2013-03-28","Type":"Other","Title":"Published"}]}}}