Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
2021-08-07T18:15:06.997
2024-11-21T06:16:32.203
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:N/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lynx_project | lynx | ≤ 2.8.9 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | fedoraproject | fedora | 33 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |