Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7473
HistorySep 13, 2018 - 6:12 a.m.

Man-in-the-Middle (MitM)

2018-09-1306:12:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.003

Percentile

68.9%

postgresql is vulnerable to man-in-the-middle. Hostname verification for non-default SSL factories are not performed if the hostname verifier is not provided to the driver. This allows an attacker to masquerade as a trusted server by providing a certificate signed by a trusted CA.