Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31778
HistoryAug 22, 2021 - 2:36 a.m.

Man-in-the-middle (MITM)

2021-08-2202:36:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

42.9%

nbdkit:sid is vulnerable to man-in-the-middle. A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session.