Описание
Rome SDK Information Disclosure Vulnerability
An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation. This vulnerability allows an unauthenticated attacker to establish connection with an invalid SSL/TLS server certificate.
To exploit this, an attacker would have to Man-In-The-Middle to intercept an established connection.
This security update addresses the issue by handling server SSL/TLS certificate validation correctly.
FAQ
What versions of the Project Rome SDK are affected by this vulnerability?
Version 1.4.0 and all previous versions of the SDK are affected. Version 1.4.1 does not have the vulnerability.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
DOS
EPSS
Связанные уязвимости
An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosure Vulnerability'.
An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosure Vulnerability'.
Уязвимость программного средства для обеспечения взаимодействия копий приложения на различных устройствах и платформах Project Rome SDK, связанная с ошибками подтверждения подлинности сертификата, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS