Description
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1528 | An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification. |
Github GHSA |
GHSA-34p9-f4q3-c4r7 | Improper Certificate Validation in openssl |
References
| Link | Providers |
|---|---|
| https://rustsec.org/advisories/RUSTSEC-2016-0001.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T03:38:56.676Z
Reserved: 2019-08-25T00:00:00.000Z
Link: CVE-2016-10931
No data.
Status : Modified
Published: 2019-08-26T12:15:11.327
Modified: 2024-11-21T02:45:06.207
Link: CVE-2016-10931
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA