PT-2020-8077 · Suse · Suse Studio
Johannes Segitz
·
Published
2020-01-27
·
Updated
2020-02-04
·
CVE-2017-14806
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
SUSE Studio onsite susestudio-common versions 1.3.17-56.6.3 and prior versions.
Description:
The issue is related to an Improper Certificate Validation vulnerability, allowing remote attackers to perform a man-in-the-middle (MITM) attack on connections to the repositories. This enables the modification of packages received over these connections.
Recommendations:
For SUSE Studio onsite susestudio-common versions 1.3.17-56.6.3 and prior versions, update to a version newer than 1.3.17-56.6.3 to resolve the issue. As a temporary workaround, consider restricting access to the repositories to minimize the risk of exploitation.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse Studio