« Volver al listado

CVE-2009-2059

Estado: ModificadaMedia (6.8)—

Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-2059",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-06-15T19:30:05.437",
  "references": [
    {
      "url": "http://research.microsoft.com/apps/pubs/default.aspx?id=79323",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://research.microsoft.com/apps/pubs/default.aspx?id=79323",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an \"SSL tampering\" attack."
    },
    {
      "lang": "es",
      "value": "Opera, posiblemente anteriores a v9.25, utiliza una cabecera HTTP Host para determinar el contexto de un documento propocionado por una respuesta de CONEXIÓN (1) 4xx o (2) 5xx desde un servidor proxy, lo que permite a los atacantes \"hombre en el medio\" ejecutar arbitrariamente una secuencia de comandos web modificando la respuesta CONEXIÓN, también conocida como un ataque \"forzado SSL\"."
    }
  ],
  "lastModified": "2026-06-16T23:08:40.713",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11F806C7-C64E-4EE7-96B1-E625CE121A88",
              "versionEndIncluding": "9.22"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7C35850-B79C-4EE4-A6F2-CC5D2304724B"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8F6644C-97E6-4023-9C5C-5C1E1B0B55D7"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.53:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7965089-8592-47F2-958B-7DBE669BCAC9"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.54:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1750B2D-7AC8-45CF-9879-1D0476EEE86C"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:7.60:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECEE4473-88C0-4E28-A5B5-F7383B0E5558"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76410AD4-78CA-48EA-83F0-099D0A49626F"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DF2B21F-7E97-416B-AF5C-35338A254552"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBAC41D6-73D4-44E9-87E4-E1E955B9580A"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52FCCB1C-165C-49FF-B70B-475B37BDF02A"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.51:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FA5A5E5-3703-44AC-9963-A20A55002B48"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.52:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC3E5BEF-3F29-4929-A37C-C49322B19047"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.53:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B0E7B5D-2568-4128-8F99-E74D24A7E991"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:8.54:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6A04906-7267-4A09-87BF-D639C7CF315B"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEA17D3F-A17B-47A6-8066-583F63D11468"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED63C1B5-F52D-4C70-82D3-B427EAF5CF4F"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98E48C83-01AE-4A33-A004-14B99792674C"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B56A2B78-70BD-439B-B1ED-A17FA5EF0990"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "623E4466-82CC-4BDD-BE25-3BB33B585547"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F90E537-5A0F-4302-9CC3-8EE7EB21DD1D"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5ECA190-D7D3-4248-A61E-0D87E67E3D31"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}