CVE-2015-1816

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
14/08/2015
Last modified:
12/04/2025

Description

Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:* 1.7.3 (including)