Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.
The product does not validate, or incorrectly validates, a certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Shotwell | Gnome | 0.22.0 (including) | 0.22.0 (including) |
| Shotwell | Ubuntu | precise | * |
| Shotwell | Ubuntu | trusty | * |
| Shotwell | Ubuntu | upstream | * |