Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-31884

Опубликовано: 20 янв. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in Ceph. An attacker can allow Ceph to accept any certificate because no certificate context is passed via Pybind to the constructors imaplib.IMAP4_SSL or smtplib.SMTP_SSL. As a result, pybind pybind does not check the server's X.509 certificate, instead accepting any certificate. This enables an attacker to commit a Man In the Middle (MITM) attack, compromising mail server credentials or mail contents

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
7 месяцев назад

Incorrect usage of certificate checking via Pybind

debian

Описание отсутствует

CVSS3: 6.5
fstec
9 месяцев назад

Уязвимость системы хранения данных Ceph, позволяющая нарушителю получить доступ к конфиденциальным данным или вызвать отказ в обслуживании

6.5 Medium

CVSS3