Security Advisory

CVE-2017-7513

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-08-22 15:00:00
Last updated 2024-08-05 16:04:11
Assigner redhat
CVSS score 5.4
State PUBLISHED

Description

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.