Description
A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the repositories, which allows the modification of packages received over these connections. This issue affects: SUSE Studio onsite susestudio-common version 1.3.17-56.6.3 and prior versions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6295 | A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the repositories, which allows the modification of packages received over these connections. This issue affects: SUSE Studio onsite susestudio-common version 1.3.17-56.6.3 and prior versions. |
References
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1065397 |
|
History
No history.
Status: PUBLISHED
Assigner: microfocus
Published:
Updated: 2024-09-16T16:48:59.649Z
Reserved: 2017-09-27T00:00:00.000Z
Link: CVE-2017-14806
No data.
Status : Modified
Published: 2020-01-27T10:15:11.247
Modified: 2024-11-21T03:13:32.490
Link: CVE-2017-14806
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD