Total vulnerabilities in the database
Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.
Software | From | Fixed in |
---|---|---|
theforeman / foreman | - | 1.7.3.x |