Security readout for executives and security teams
GNOME Online Accounts had an SSL certificate validation flaw during account creation for providers using libsoup. A person positioned on the network could intercept the setup flow and capture sensitive data, including credentials. The issue affected GOA 3.6.x before 3.6.3 and 3.7.x before 3.7.91. Exposure is most likely on legacy Linux desktop environments running GNOME Online Accounts 3.6.x before 3.6.3 or 3.7.x before 3.7.91, especially where users created online accounts over untrusted or intercepted networks. Treat this as high priority for legacy desktop environments because credential exposure is the business impact. For modern fleets, urgency depends on whether vulnerable GOA versions still exist; validate through inventory rather than assuming exposure. Mitigation focus: Upgrade GNOME Online Accounts to 3.6.3, 3.7.91, or a vendor-fixed package.; Review Ubuntu and openSUSE advisories for distribution-specific package guidance.; Prioritize legacy GNOME desktop images and long-lived workstations for inventory review..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2013-1799 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- [gnome-announce-list] 20130305 GNOME Online Accounts 3.7.91 releasedCVE reference · mailing-list, x_refsource_MLIST
- https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8CVE reference · x_refsource_CONFIRM
- [gnome-announce-list] 20130304 GNOME Online Accounts 3.6.3 releasedCVE reference · mailing-list, x_refsource_MLIST
- https://bugzilla.gnome.org/show_bug.cgi?id=695106CVE reference · x_refsource_CONFIRM
- https://bugzilla.gnome.org/show_bug.cgi?id=693214CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
