CVE-2017-1000024

EUVD-2017-1353
Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Affected Products (NVD)
VendorProductVersion
gnomeshotwell
0.24.0 ≤
𝑥
≤ 0.24.4
gnomeshotwell
0.25.0 ≤
𝑥
≤ 0.25.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
shotwell
bookworm
0.30.17-1
fixed
bullseye
0.30.11-1
fixed
sid
0.32.7-1
fixed
trixie
0.32.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
shotwell
trusty
Fixed 0.18.0-0ubuntu4.5
released
xenial
Fixed 0.22.0+git20160108.r1.f2fb1f7-0ubuntu1.1
released
yakkety
ignored
zesty
Fixed 0.22.0+git20160108.r1.f2fb1f7-0ubuntu3.1
released