Summary: logback SSL Certificate Validation Failure MitM Spoofing
Severity: MEDIUM
Description: logback contains a flaw as X.509 certificates are not properly validated. By spoofing the TLS/SSL server via a certificate that appears valid, an attacker with the ability to intercept network traffic (e.g. MitM, DNS cache poisoning) can disclose and optionally manipulate transmitted data.
Type: SECURITY
Provider: JFrog
Issues: 4.0/CVSS:2.0/AV:N/AC:H/Au:N/C:P/I:P/A:N
Edited: 2021-04-15T09:22:04Z
Created: 2019-05-02T00:00:00.297Z