Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24026
HistoryApr 10, 2020 - 12:44 a.m.

Man-in-the-Middle (MitM)

2020-04-1000:44:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.003 Low

EPSS

Percentile

66.0%

openldap is vulnerable to man-in-the-middle (MitM). The vulnerability exists as a flaw was found in the way OpenLDAP handled NUL characters in the CommonName field of X.509 certificates. An attacker able to get a carefully-crafted certificate signed by a trusted Certificate Authority could trick applications using OpenLDAP libraries into accepting it by mistake.

References