CVE-2017-1000024

Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
gnomeshotwell
0.24.0 ≤
𝑥
≤ 0.24.4
gnomeshotwell
0.25.0 ≤
𝑥
≤ 0.25.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
shotwell
bullseye
0.30.11-1
fixed
bookworm
0.30.17-1
fixed
sid
0.32.7-1
fixed
trixie
0.32.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
shotwell
zesty
Fixed 0.22.0+git20160108.r1.f2fb1f7-0ubuntu3.1
released
yakkety
ignored
xenial
Fixed 0.22.0+git20160108.r1.f2fb1f7-0ubuntu1.1
released
trusty
Fixed 0.18.0-0ubuntu4.5
released