When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
| Software | From | Fixed in |
|---|---|---|
| adacore / ada_web_server | 25.0 | 25.0.x |
| debian / debian_linux | 11.0 | 11.0.x |