Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h32x-w4cv-wrq9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

EPSS

Процентиль: 23%
0.00079
Низкий

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 3.1
redhat
больше 5 лет назад

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

CVSS3: 5.4
nvd
около 5 лет назад

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

EPSS

Процентиль: 23%
0.00079
Низкий

Дефекты

CWE-295