AI Score
Confidence
Low
EPSS
Percentile
39.8%
Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.
projects.theforeman.org/issues/9858
access.redhat.com/errata/RHSA-2015:1591
access.redhat.com/errata/RHSA-2015:1592
github.com/theforeman/foreman/pull/2265
groups.google.com/forum/#%21topic/foreman-announce/9ZnuPcplNLI