PT-2020-15143 · Facebook · Osquery
Alessandro Gario
+1
·
Published
2020-03-12
·
Updated
2020-04-03
·
CVE-2020-1887
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
osquery versions 2.9.0 through 4.2.0
Description
The issue is related to incorrect validation of the TLS SNI hostname, which could allow an attacker to perform a man-in-the-middle (MITM) attack on osquery traffic when a root chain of trust is not configured. This could potentially affect osquery communications.
Recommendations
For osquery versions 2.9.0 through 4.2.0, update to version 4.2.0 or later to resolve the issue.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Osquery