Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76rg-wcxr-453v

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.

Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.

EPSS

Процентиль: 75%
0.00906
Низкий

Связанные уязвимости

ubuntu
больше 21 года назад

Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.

nvd
больше 21 года назад

Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.

debian
больше 21 года назад

Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 ...

EPSS

Процентиль: 75%
0.00906
Низкий