CVE Vulnerabilities

CVE-2017-1000024

Cleartext Transmission of Sensitive Information

Published: Jul 17, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Shotwell Gnome 0.24.0 (including) 0.24.4 (including)
Shotwell Gnome 0.25.0 (including) 0.25.3 (including)
Shotwell Ubuntu devel *
Shotwell Ubuntu esm-infra/xenial *
Shotwell Ubuntu trusty *
Shotwell Ubuntu upstream *
Shotwell Ubuntu xenial *
Shotwell Ubuntu yakkety *
Shotwell Ubuntu zesty *

Potential Mitigations

References