Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25680

Опубликовано: 29 окт. 2020
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

Дополнительная информация

Статус:

Low
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1892703httpd: allow connecting via SSL to a backend worker when the backend keystore file's ID is 'unknown'

EPSS

Процентиль: 23%
0.00079
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 5 лет назад

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

github
больше 3 лет назад

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

EPSS

Процентиль: 23%
0.00079
Низкий

3.1 Low

CVSS3