PT-2025-8751 · Adacore+2 · Aws.Client+3
Published
2025-02-26
·
Updated
2025-04-07
·
CVE-2024-55581
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
AdaCore Ada Web Server version 25.0.0
Description
The issue concerns a lack of verification of an HTTPS server's certificate in the default behaviour of AWS.Client when linked with GnuTLS, making it vulnerable to a man-in-the-middle attack. This occurs unless the using program specifies a TLS configuration.
Recommendations
For AdaCore Ada Web Server version 25.0.0, consider specifying a TLS configuration in the using program to enable verification of an HTTPS server's certificate and mitigate the risk of a man-in-the-middle attack. As a temporary workaround, restrict the use of AWS.Client with default settings to minimize the risk of exploitation.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws.Client
Ada Web Server
Debian
Gnutls