Beveiligingsadvies

CVE-2017-7513

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-08-22 15:00:00
Laatst bijgewerkt 2024-08-05 16:04:11
Toegewezen door redhat
CVSS-score 5.4
Status PUBLISHED

Beschrijving

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.