ZeroHour

CVE-2017-7513

CVSS 3.0
5.4 medium
EPSS
<1%p40
Published
()
Modified
Description

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.

Vendors
redhat
Products
satellite
Weakness
CWE-295
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.