CVE-2017-8822
Estado: ModificadaBaja (3.7)—
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.90%
- Percentil entre todas las CVEs puntuadas: 58
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-417
Referencias
- https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516
- https://bugs.torproject.org/21534
- https://bugs.torproject.org/24333
- https://www.debian.org/security/2017/dsa-4054
- https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516
- https://bugs.torproject.org/21534
- https://bugs.torproject.org/24333
- https://www.debian.org/security/2017/dsa-4054
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-8822",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "security@debian.org",
"affectedData": [
{
"vendor": "n/a",
"product": "Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9",
"versions": [
{
"status": "affected",
"version": "Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9"
}
]
}
]
}
],
"published": "2017-12-03T07:29:00.413",
"references": [
{
"url": "https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516",
"tags": [
"Vendor Advisory"
],
"source": "security@debian.org"
},
{
"url": "https://bugs.torproject.org/21534",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "security@debian.org"
},
{
"url": "https://bugs.torproject.org/24333",
"tags": [
"Vendor Advisory"
],
"source": "security@debian.org"
},
{
"url": "https://www.debian.org/security/2017/dsa-4054",
"tags": [
"Third Party Advisory"
],
"source": "security@debian.org"
},
{
"url": "https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.torproject.org/21534",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.torproject.org/24333",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.debian.org/security/2017/dsa-4054",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-417"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012."
},
{
"lang": "es",
"value": "En Tor, en versiones anteriores a la 0.2.5.16; de la versión 0.2.6 hasta la 0.2.8 anterior a la 0.2.8.17; versiones 0.2.9 anteriores a la 0.2.9.14; versiones 0.3.0 anteriores a la 0.3.0.13 y versiones 0.3.1 anteriores a la 0.3.1.9, los relays (que contienen descriptores descargados de forma incompleta) pueden escogerse a sí mismos en una ruta, lo que da lugar a una degradación de anonimato. Esto también se conoce como TROVE-2017-012."
}
],
"lastModified": "2026-06-17T01:27:01.473",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "067DE048-F786-4E63-98E6-6FD6415DD3A5",
"versionEndExcluding": "0.2.5.16"
},
{
"criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5372249B-59F8-4866-B4D3-F52980FCC269",
"versionEndExcluding": "0.2.8.17",
"versionStartIncluding": "0.2.6"
},
{
"criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0739CCD-DE8F-4A44-91CD-986C4644045F",
"versionEndExcluding": "0.2.9.14",
"versionStartIncluding": "0.2.9"
},
{
"criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E623D0FC-453C-4D7A-8328-C4C252EEC976",
"versionEndExcluding": "0.3.0.13",
"versionStartIncluding": "0.3.0"
},
{
"criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "249879F0-6A12-41C2-9559-020021080696",
"versionEndExcluding": "0.3.1.9",
"versionStartIncluding": "0.3.1"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@debian.org"
}