Amazon Web Services SDK SSL Certificate Validation Security Bypass Vulnerability
BID:56451
Info
Amazon Web Services SDK SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 56451 |
| Class: | Design Error |
| CVE: |
CVE-2012-5780 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2012 12:00AM |
| Updated: | Nov 04 2012 12:00AM |
| Credit: | Reported at the ACM CCS 2012 conference |
| Vulnerable: |
Amazon Amazon Web Services SDK 0 |
| Not Vulnerable: | |
Discussion
Amazon Web Services SDK SSL Certificate Validation Security Bypass Vulnerability
Amazon Web Services SDK is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from a server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid further attacks.
Amazon Web Services SDK is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from a server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid further attacks.