漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Mastodon: Unwanted deactivation of SSL/TLS certificate verification
Vulnerability Description
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
证书验证不恰当
Vulnerability Title
Mastodon 加密问题漏洞
Vulnerability Description
Mastodon是Mastodon组织的一款去中心化社交网络服务器软件。 Mastodon 4.4.19之前版本和4.5.0至4.5.12之前版本存在加密问题漏洞,该漏洞源于LDAP认证使用LDAP_TLS_NO_VERIFY=true时修改OpenSSL默认参数,导致SSL和TLS证书验证被全局禁用。
CVSS Information
N/A
Vulnerability Type
N/A