Описание
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 8.20.0-2ubuntu1 |
| esm-infra-legacy/trusty | ignored | changes too intrusive |
| esm-infra-legacy/xenial | ignored | changes too intrusive |
| esm-infra/bionic | ignored | changes too intrusive |
| esm-infra/focal | ignored | changes too intrusive |
| esm-infra/xenial | ignored | end of ESM support, was needed |
| jammy | released | 7.81.0-1ubuntu1.24 |
| noble | released | 8.5.0-2ubuntu10.9 |
| questing | released | 8.14.1-2ubuntu1.3 |
| resolute | released | 8.18.0-1ubuntu2.1 |
Показывать по
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.
A vulnerability exists where a connection requiring TLS incorrectly re ...
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.
EPSS
5.9 Medium
CVSS3