Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
lettre has TLS hostname verification disabled when using Boring TLS backend
Vulnerability Description
lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS hostname verification for callers using the default (strict) configuration. An on-path attacker presenting any chain-valid certificate for any domain can intercept SMTP submission, including PLAIN/LOGIN credentials and message contents, against any lettre user built with the `boring-tls` feature. Other TLS backends (`native-tls`, `rustls`) are unaffected. Version 0.11.22 patches the issue.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Vulnerability Type
证书验证不恰当
Vulnerability Title
lettre 加密问题漏洞
Vulnerability Description
lettre是lettre个人开发者开源的一套电子邮件发送库。 lettre 0.10.1版本至0.11.22之前版本存在加密问题漏洞,该漏洞源于boring-tls集成中的倒布尔错误导致TLS主机名验证被静默禁用,可能允许路径上的攻击者使用任何域的有效证书拦截SMTP提交,包括PLAIN/LOGIN凭据和消息内容。
CVSS Information
N/A
Vulnerability Type
N/A