Magento SSL Certificate Validation Security Bypass Vulnerability
BID:56453
Info
Magento SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 56453 |
| Class: | Design Error |
| CVE: |
CVE-2011-5240 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2012 12:00AM |
| Updated: | Nov 06 2012 12:00AM |
| Credit: | Reported at the ACM CCS 2012 conference |
| Vulnerable: |
Magento Magento 1.6.2 Magento Magento 1.5 |
| Not Vulnerable: | |
Discussion
Magento SSL Certificate Validation Security Bypass Vulnerability
Magento is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from a server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid further attacks.
Magento 1.5 and 1.6.2 are vulnerable.
Magento is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from a server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid further attacks.
Magento 1.5 and 1.6.2 are vulnerable.