Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5g62-v8vq-wrxx

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

EPSS

Процентиль: 49%
0.00257
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 13 лет назад

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

redhat
почти 14 лет назад

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

nvd
больше 13 лет назад

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

debian
больше 13 лет назад

libsoup 2.32.2 and earlier does not validate certificates or clear the ...

EPSS

Процентиль: 49%
0.00257
Низкий

Дефекты

CWE-287