CVE-2024-48460

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
16/01/2025
Last modified:
03/02/2025

Description

An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.

References to Advisories, Solutions, and Tools