Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cyberduck and Mountain Duck - Improper Certificate Store Handling
Vulnerability Description
Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
特权授予不正确
Vulnerability Title
iterate Cyberduck和iterate Mountain Duck 安全漏洞
Vulnerability Description
iterate Cyberduck和iterate Mountain Duck都是iterate开源的一款文件传输客户端。 iterate Cyberduck 9.1.6及之前版本和iterate Mountain Duck 4.17.5及之前版本存在安全漏洞,该漏洞源于TLS证书固定处理不当,可能导致安装不受信任证书。
CVSS Information
N/A
Vulnerability Type
N/A