Quantcast
Channel: Security Bulletins
Viewing all articles
Browse latest Browse all 25

Community App Center Improper SSL Certificate Verification Vulnerability

$
0
0

Publish Date: Nov. 19, 2018

Summary

We've identified and fixed a vulnerability in the Spiceworks Community App Center concerning an improper SSL Certificate Verification upon logging in through certain endpoints.

Who’s Affected?

At this time we do not believe anyone was impacted by this vulnerability.

Details

When logging in to Spiceworks through the App Center using a certain API, the connection happened over a secure connection. The SSL certificate verification, however, was done in a way that is no longer supported in modern browsers. It used “Common Name” to identify the host name associated with the certificate instead of the now required “Subject Alternative Name”. Some browsers, like Safari, will use unencrypted connections when this happens, while others, like Chrome and Firefox, just display a warning page.

Mitigating Factors...

Viewing all articles
Browse latest Browse all 25

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>