Back

MEDIUM

Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API

Published Jul 9, 2019

Description

Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelope, assuming the private key password is cached. A second vulnerability allows an attacker to decrypt an arbitrary message when the GnuPG backend is used in Mailvelope.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 9, 2019
Updated Aug 4, 2024
Reserved Feb 25, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a