CVE-2019-9148

CVE-2019-9148

Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contain users without a valid self-certification. Keys that are obviously invalid are not rejected during import. An attacker that is able to get a victim to import a manipulated key could claim to have signed a message that originates from another person.

Source: CVE-2019-9148

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다