CVE-2018-18908: Medium severity sky go vulnerability
The Sky Go Desktop application 1.0.19-1 through 1.0.23-1 for Windows performs several requests over cleartext HTTP. This makes the data submitted in these requests prone to Man in The Middle (MiTM) attacks, whereby an attacker would be able to obtain the data sent in these requests. Some of the requests contain potentially sensitive information that could be useful to an attacker, such as the victim's Sky username.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
Sky Go Desktop for Windows versions 1.0.19-1 through 1.0.23-1 are identified as affected.
What does an attacker need to exploit this issue?
An attacker needs the ability to perform a man-in-the-middle attack on the victim's network traffic. No authentication or user interaction is required according to the supplied CVSS vector.
What information could be exposed?
Data sent in several cleartext HTTP requests may be intercepted. Some requests can contain potentially sensitive information, including the victim's Sky username.