Описание
Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 1.9.2+dfsg-1 |
| bionic | not-affected | 1.9.2+dfsg-1 |
| cosmic | not-affected | 1.9.2+dfsg-1 |
| devel | not-affected | 1.9.2+dfsg-1 |
| disco | not-affected | 1.9.2+dfsg-1 |
| eoan | not-affected | 1.9.2+dfsg-1 |
| esm-apps/bionic | not-affected | 1.9.2+dfsg-1 |
| esm-apps/focal | not-affected | 1.9.2+dfsg-1 |
| esm-apps/jammy | not-affected | 1.9.2+dfsg-1 |
| esm-apps/noble | not-affected | 1.9.2+dfsg-1 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Ansible before 1.9.2 does not verify that the server hostname matches ...
Ansible does not verify that the server hostname matches a domain name in certificates
EPSS
4.3 Medium
CVSS2