脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Attacker can prevent users from accessing received emails
脆弱性説明
Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so that the user can no longer use the app to get access to received emails. By sending a manipulated email, an attacker could put the app into an unusable state. In this case, a user can no longer access received e-mails. Since the vulnerability affects not only the app, but also the web application, a user in this case has no way to access received emails. This issue was tested with iOS and the web app, but it is possible all clients are affected. Version 3.119.10 fixes this issue.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
脆弱性タイプ
输入验证不恰当
脆弱性タイトル
Tutanota 输入验证错误漏洞
脆弱性説明
Tutanota是Tuta公司的一项非常注重安全和隐私的电子邮件服务,可加密所有设备上的电子邮件、联系人和日历条目。 Tutanota 3.118.12 到 3.119.10版本存在输入验证错误漏洞,该漏洞源于攻击者能够发送被操纵的电子邮件,使用户无法再使用该应用程序来访问收到的电子邮件。
CVSS情報
N/A
脆弱性タイプ
N/A