Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3839
HistoryApr 05, 2017 - 2:01 a.m.

Man-in-the-Middle (MitM)

2017-04-0502:01:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.001 Low

EPSS

Percentile

48.6%

ansible is vulnerable to man-in-the-middle (MitM) attacks. The vulnerability exists because it does not perform ample validation of HTTPS certificate using get_url and uri modules. Therefore, it fails to catch the mismatch between server hostname and a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate, allowing the attacker to spoof the certificate and launch the MitM attack.