PT-2018-13950 · Postman · Postman
Ludwig Stage
·
Publicado
2018-09-26
·
Atualizado
2024-02-01
·
CVE-2018-17215
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Postman versions through 6.3.0
Description
An information-disclosure issue was discovered in Postman. It validates a server's X.509 certificate and presents an error if the certificate is not valid. Unfortunately, the associated HTTPS request data is sent anyway, with only the response not being displayed. Thus, all contained information of the HTTPS request is disclosed to a man-in-the-middle attacker, for example, user credentials.
Recommendations
For Postman versions through 6.3.0, update to a version later than 6.3.0 to resolve the issue. As a temporary workaround, consider disabling HTTPS requests in Postman until a patch is available. Restrict access to sensitive information when using Postman to minimize the risk of exploitation. Avoid using Postman to send sensitive information over HTTPS until the issue is resolved.
Exploit
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Postman