Описание
Incorrect usage of certificate checking via Pybind
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 20.2.0-0ubuntu2 |
| esm-infra-legacy/trusty | not-affected | 15.1.0+ only |
| esm-infra-legacy/xenial | not-affected | 15.1.0+ only |
| esm-infra/bionic | not-affected | 15.1.0+ only |
| esm-infra/focal | released | 15.2.17-0ubuntu0.20.04.6+esm1 |
| esm-infra/xenial | not-affected | 15.1.0+ only |
| jammy | released | 17.2.9-0ubuntu0.22.04.2 |
| noble | released | 19.2.3-0ubuntu0.24.04.3 |
| questing | released | 19.2.3-0ubuntu1.25.10.3 |
| resolute | not-affected | 20.2.0-0ubuntu2 |
Показывать по
10
Связанные уязвимости
CVSS3: 6.5
redhat
7 месяцев назад
A flaw was found in Ceph. An attacker can allow Ceph to accept any certificate because no certificate context is passed via Pybind to the constructors imaplib.IMAP4_SSL or smtplib.SMTP_SSL. As a result, pybind pybind does not check the server's X.509 certificate, instead accepting any certificate. This enables an attacker to commit a Man In the Middle (MITM) attack, compromising mail server credentials or mail contents
CVSS3: 6.5
fstec
9 месяцев назад
Уязвимость системы хранения данных Ceph, позволяющая нарушителю получить доступ к конфиденциальным данным или вызвать отказ в обслуживании