Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2024-31884
April 07, 2024
A flaw was found in Ceph. An attacker can allow Ceph to accept anycertificate because no certificate context is passed via Pybind to theconstructors imaplib.IMAP4_SSL or smtplib.SMTP_SSL. As a result, pybind pybinddoes not check the server's X.509certificate, instead accepting any certificate. This enables an attacker tocommit a Man In the Middle (MITM) attack, compromising mail servercredentials or mail contents
Do you need more information?
Contact Us
CVSS v3
Base Score:
6.5
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE