CVE-2017-17455 - Improper Certificate Validation vulnerability in Mahara

Publication

2018-02-20

Last modification

2018-03-16

Summary

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

Classification

CWE-295 - Improper Certificate Validation

Risk level (CVSS AV:N/AC:M/Au:N/C:P/I:N/A:N)

Medium

4.3

Access Vector

  • Network
  • Adjacent Network
  • Local

Access Complexity

  • Low
  • Medium
  • High

Authentication

  • None
  • Single
  • Multiple

Confident. Impact

  • Complete
  • Partial
  • None

Integrity Impact

  • Complete
  • Partial
  • None

Affected Products

Related CVE