Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10955
HistoryJan 15, 2019 - 8:54 a.m.

Information Disclosure

2019-01-1508:54:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22

0.975 High

EPSS

Percentile

100.0%

OpenSSL is vulnerable to information disclosure. This is possible because the SSL protocol 3.0 uses a nondeterministic CBC padding allowing attackers to perform man-in-the-middle (MitM) attacks. This is also known as the POODLE issue.

References