CVE-2018-17215 is an information disclosure vulnerability affecting Postman through version 6.3.0. Despite invalid X.509 certificates, Postman sends HTTPS request data, allowing a man-in-the-middle attacker to intercept sensitive information like user credentials. This vulnerability carries a CVSS score of 8.1 (HIGH), indicating a high-impact attack with network access and high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.3.0CPE matchmatch criteria | cpe:2.3:a:postman:postman:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.