CVE-2017-17455

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
20/02/2018
Last modified:
16/03/2018

Description

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 16.10.0 (including) 16.10.7 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 17.04.0 (including) 17.04.5 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 17.10.0 (including) 17.10.2 (excluding)