PT-2018-13950 · Postman · Postman

Ludwig Stage

·

Publicado

2018-09-26

·

Atualizado

2024-02-01

·

CVE-2018-17215

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Postman versions through 6.3.0
Description An information-disclosure issue was discovered in Postman. It validates a server's X.509 certificate and presents an error if the certificate is not valid. Unfortunately, the associated HTTPS request data is sent anyway, with only the response not being displayed. Thus, all contained information of the HTTPS request is disclosed to a man-in-the-middle attacker, for example, user credentials.
Recommendations For Postman versions through 6.3.0, update to a version later than 6.3.0 to resolve the issue. As a temporary workaround, consider disabling HTTPS requests in Postman until a patch is available. Restrict access to sensitive information when using Postman to minimize the risk of exploitation. Avoid using Postman to send sensitive information over HTTPS until the issue is resolved.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17215

Produtos afetados

Postman