Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3908

Опубликовано: 19 июн. 2015
Источник: redhat
CVSS2: 7.6
EPSS Низкий

Описание

Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 3ansibleNot affected
Red Hat OpenStack Platform 10 (Newton)ansibleNot affected
Red Hat Quickstart Cloud Installer 1ansibleNot affected
Red Hat Storage 3.0ansibleNot affected
Red Hat Storage Console 2ansibleNot affected

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1243468ansible: multiple issues fixed in 1.9.2

EPSS

Процентиль: 24%
0.0008
Низкий

7.6 High

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

nvd
больше 10 лет назад

Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

debian
больше 10 лет назад

Ansible before 1.9.2 does not verify that the server hostname matches ...

CVSS3: 7.5
github
больше 7 лет назад

Ansible does not verify that the server hostname matches a domain name in certificates

EPSS

Процентиль: 24%
0.0008
Низкий

7.6 High

CVSS2