Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23764
HistoryApr 10, 2020 - 12:35 a.m.

Man-in-the-Middle (MitM)

2020-04-1000:35:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.001 Low

EPSS

Percentile

51.0%

curl is vulnerable to man-in-the-middle attack. A null prefix attack caused by incorrect handling of NULL characters in X.509 certificates allows an attacker obtain a carefully-crafted certificate signed by a trusted Certificate Authority, the attacker could use the certificate during a man-in-the-middle attack and potentially confuse cURL into accepting it by mistake.

References