A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-08-05 14:15
Updated : 2024-09-25 01:15
NVD link : CVE-2024-7383
Mitre link : CVE-2024-7383
CVE.ORG link : CVE-2024-7383
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation