Описание
Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.
Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2015-1816
- https://github.com/theforeman/foreman/pull/2265
- https://access.redhat.com/errata/RHSA-2015:1591
- https://access.redhat.com/errata/RHSA-2015:1592
- https://groups.google.com/forum/#!topic/foreman-announce/9ZnuPcplNLI
- https://groups.google.com/forum/#%21topic/foreman-announce/9ZnuPcplNLI
- http://projects.theforeman.org/issues/9858
EPSS
Процентиль: 44%
0.00217
Низкий
CVE ID
Связанные уязвимости
redhat
почти 11 лет назад
Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.
nvd
больше 10 лет назад
Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.
debian
больше 10 лет назад
Forman before 1.7.4 does not verify SSL certificates for LDAP connecti ...
EPSS
Процентиль: 44%
0.00217
Низкий