脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Missing TLS certificate verification in Faye
脆弱性説明
Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes. Faye uses em-http-request and faye-websocket in the Ruby version of its client. Those libraries both use the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever a `wss:` URL is used for the connection. This method does not implement certificate verification by default, meaning that it does not check that the server presents a valid and trusted TLS certificate for the expected hostname. That means that any `https:` or `wss:` connection made using these libraries is vulnerable to a man-in-the-middle attack, since it does not confirm the identity of the server it is connected to. The first request a Faye client makes is always sent via normal HTTP, but later messages may be sent via WebSocket. Therefore it is vulnerable to the same problem that these underlying libraries are, and we needed both libraries to support TLS verification before Faye could claim to do the same. Your client would still be insecure if its initial HTTPS request was verified, but later WebSocket connections were not. This is fixed in Faye v1.4.0, which enables verification by default. For further background information on this issue, please see the referenced GitHub Advisory.
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
脆弱性タイプ
证书验证不恰当
脆弱性タイトル
Faye 信任管理问题漏洞
脆弱性説明
Faye是James Coglan软件开发者的一套开源的基于Bayeux协议的发布-订阅消息系统。该系统主要用于在Web客户端之间进行发布-订阅消息传递。 Faye 1.4.0之前版本中存信任管理问题漏洞,该漏洞源于在TLS握手过程中,程序没有进行证书检查。攻击者可利用该漏洞实施中间人攻击。
CVSS情報
N/A
脆弱性タイプ
N/A