PT-2015-6380 · Apple · Afnetworking
Publicado
2015-10-27
·
Atualizado
2015-10-28
·
CVE-2015-3996
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
AFNetworking framework versions prior to 2.5.3
Description
The issue concerns the default configuration of AFSecurityPolicy.validatesDomainName for AFSSLPinningModeNone in the AFNetworking framework. This configuration disables the verification of a server's hostname against the domain name in the subject's Common Name (CN) of the X.509 certificate. As a result, it allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Recommendations
For AFNetworking framework versions prior to 2.5.3, update to version 2.5.3 or later to enable the verification of a server's hostname against the domain name in the subject's Common Name (CN) of the X.509 certificate.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Afnetworking