An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecated TLS version.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p3pf-mff8-3h47 Gorush uses deprecated TLS versions
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 13 Aug 2024 03:45:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:appleboy:gorush:*:*:*:*:*:go:*:*

Thu, 08 Aug 2024 00:30:00 +0900

Type Values Removed Values Added
First Time appeared Appleboy
Appleboy gorush
Weaknesses CWE-327
CPEs cpe:2.3:a:appleboy:gorush:*:*:*:*:*:*:*:*
Vendors & Products Appleboy
Appleboy gorush
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Aug 2024 06:00:00 +0900

Type Values Removed Values Added
Description An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecated TLS version.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T14:38:53.704Z

Reserved: 2024-07-18T00:00:00

Link: CVE-2024-41270

cve-icon Vulnrichment

Updated: 2024-08-07T14:38:46.300Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-06T21:16:03.223

Modified: 2024-08-12T18:25:28.583

Link: CVE-2024-41270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses