Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7860
HistoryNov 20, 2018 - 8:55 a.m.

Certificate Spoofing

2018-11-2008:55:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

46.1%

vt-ldap is vulnerable to certificate spoofing. The library does not properly parse and verify the hostname in certificates, allowing an attacker to spoof SSL Servers by spoofing a certificate in conjunction with a man-in-the-middle (MitM) attack.

EPSS

0.001

Percentile

46.1%