CVE-2016-1000033

LOW

Shotwell <0.22.0 - SSL Validation Flaw

Title source: llm
STIX 2.1

Description

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

References (1)

Core 1
Core References
Issue Tracking x_refsource_misc
https://bugzilla.gnome.org/show_bug.cgi?id=754488

Scores

CVSS v3 3.7
EPSS 0.0041
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-295
Status published
Products (2)
gnome/shotwell 0.22.0
redhat/enterprise_linux 7.0
Published Oct 25, 2016
Tracked Since Feb 18, 2026