CVE-2024-55581

When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
Configurations

No configuration.

History

10 Mar 2025, 20:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/03/msg00007.html -

04 Mar 2025, 20:15

Type Values Removed Values Added
CWE CWE-295
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4
References () https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf - () https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf -
Summary
  • (es) Cuando AdaCore Ada Web Server 25.0.0 está vinculado con GnuTLS, el comportamiento predeterminado de AWS.Client es vulnerable a un ataque de intermediario debido a la falta de verificación del certificado de un servidor HTTPS (a menos que el programa que lo utiliza especifique una configuración TLS).

26 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 22:15

Updated : 2025-03-10 20:15


NVD link : CVE-2024-55581

Mitre link : CVE-2024-55581

CVE.ORG link : CVE-2024-55581


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation