Vulnerability Details CVE-2018-1000858
GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in the composer window of Thunderbird/Enigmail. This vulnerability appears to have been fixed in after commit 4a4bb874f63741026bd26264c43bb32b1099f060.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2018-1000858
-
cpe:2.3:a:gnupg:gnupg:2.1.12
-
cpe:2.3:a:gnupg:gnupg:2.1.13
-
cpe:2.3:a:gnupg:gnupg:2.1.14
-
cpe:2.3:a:gnupg:gnupg:2.1.15
-
cpe:2.3:a:gnupg:gnupg:2.1.16
-
cpe:2.3:a:gnupg:gnupg:2.1.17
-
cpe:2.3:a:gnupg:gnupg:2.1.18
-
cpe:2.3:a:gnupg:gnupg:2.1.19
-
cpe:2.3:a:gnupg:gnupg:2.1.20
-
cpe:2.3:a:gnupg:gnupg:2.1.21
-
cpe:2.3:a:gnupg:gnupg:2.1.22
-
cpe:2.3:a:gnupg:gnupg:2.2.0
-
cpe:2.3:a:gnupg:gnupg:2.2.1
-
cpe:2.3:a:gnupg:gnupg:2.2.10
-
cpe:2.3:a:gnupg:gnupg:2.2.11
-
cpe:2.3:a:gnupg:gnupg:2.2.2
-
cpe:2.3:a:gnupg:gnupg:2.2.3
-
cpe:2.3:a:gnupg:gnupg:2.2.4
-
cpe:2.3:a:gnupg:gnupg:2.2.5
-
cpe:2.3:a:gnupg:gnupg:2.2.6
-
cpe:2.3:a:gnupg:gnupg:2.2.7
-
cpe:2.3:a:gnupg:gnupg:2.2.8
-
cpe:2.3:a:gnupg:gnupg:2.2.9
-
cpe:2.3:o:canonical:ubuntu_linux:18.04
-
cpe:2.3:o:canonical:ubuntu_linux:18.10