Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8pjf-mf88-ccv8

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

EPSS

Процентиль: 38%
0.00163
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

CVSS3: 7.5
nvd
почти 8 лет назад

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

CVSS3: 7.5
debian
почти 8 лет назад

mod-gnutls does not validate client certificates when "GnuTLSClientVer ...

EPSS

Процентиль: 38%
0.00163
Низкий

7.5 High

CVSS3