Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signed and expired, are accepted by the client. This attack appear to be exploitable via The victim connects to a server that's MITM/Proxied by an attacker.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
daneren2005 DSub for Subsonic 安全漏洞
Vulnerability Description
daneren2005 DSub for Subsonic(Android client)是一款基于Android平台、适用于Subsonic服务器的音乐流媒体应用程序。 daneren2005 DSub for Subsonic (Android客户端)5.4.1版本中的HTTPS客户端中存在安全漏洞,该漏洞源于程序没有正确的验证凭证。攻击者可利用该漏洞造成客户端接收任意的non-CA签名服务器凭证。
CVSS Information
N/A
Vulnerability Type
N/A