Vulnerability record · CVE-2018-1000858 · published 20 December 2018
CVE-2018-1000858: Gnupg cross-site request forgery vulnerability
Gnupg · Gnupg
GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in the composer window of Thunderbird/Enigmail. This vulnerability appears to have been fixed in after commit 4a4bb874f63741026bd26264c43bb32b1099f060.
Description
GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in the composer window of Thunderbird/Enigmail. This vulnerability appears to have been fixed in after commit 4a4bb874f63741026bd26264c43bb32b1099f060.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sektioneins.de/en/advisories/advisory-012018-gnupg-wkd.html | ExploitThird Party Advisory |
| https://sektioneins.de/en/blog/18-11-23-gnupg-wkd.html | Third Party Advisory |
| https://usn.ubuntu.com/3853-1/ | Third Party Advisory |
| https://sektioneins.de/en/advisories/advisory-012018-gnupg-wkd.html | ExploitThird Party Advisory |
| https://sektioneins.de/en/blog/18-11-23-gnupg-wkd.html | Third Party Advisory |
| https://usn.ubuntu.com/3853-1/ | Third Party Advisory |
Track CVE-2018-1000858 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1000858), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.