{ "schema_version": "1.4.0", "id": "GHSA-x3x6-8w8x-2p8g", "modified": "2022-05-24T17:07:03Z", "published": "2022-05-24T17:07:03Z", "aliases": [ "CVE-2020-7213" ], "details": "Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web site.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7213" }, { "type": "WEB", "url": "https://parallels.com" }, { "type": "WEB", "url": "http://almorabea.net/cves/cve-2020-7213.txt" }, { "type": "WEB", "url": "http://almorabea.net/en/2020/01/19/write-up-for-the-parallel-vulnerability-cve-2020-7213" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-01-21T17:15:00Z" } }