← Back

CVE-2013-7110

nvd nist
Published: May 2, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2073.

Affected (9)

Products: Transifex: Transifex
1 product
Transifex
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Transifex
Up to 0.9
Version 0.1
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6
Version 0.7
Version 0.8

References (6)

Timeline

No history available yet.