Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18069
HistoryMay 02, 2019 - 6:11 a.m.

Certificate Validation Bypass

2019-05-0206:11:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2

0.002 Low

EPSS

Percentile

61.0%

CloudForms is vulnerable to certificate validation bypass. This is because CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. An attacker could potentially harvest sensitive information from CloudForms by spoof RHEV or OpenShift systems.

References

0.002 Low

EPSS

Percentile

61.0%

Related for VERACODE:18069