CVE-2019-9149

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/07/2019
Last modified:
18/04/2022

Description

Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelope, assuming the private key password is cached. A second vulnerability allows an attacker to decrypt an arbitrary message when the GnuPG backend is used in Mailvelope.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mailvelope:mailvelope:*:*:*:*:*:*:*:* 3.3.0 (excluding)