CiviCRM Vulnerability in SSL Server Verification
CVE-2011-5239

Currently unrated

Key Information:

Vendor

Civicrm

Status
Vendor
CVE Published:
6 November 2012

What is CVE-2011-5239?

The CiviCRM versions 4.0.5 and 4.1.1 are susceptible to an improper SSL certificate verification flaw. This vulnerability occurs because the affected versions do not ensure that the server's hostname corresponds with the domain name specified in the Common Name (CN) or the subjectAltName field of its X.509 certificate. As a result, an attacker could exploit this oversight to perform man-in-the-middle attacks by presenting a legitimate certificate that does not match the intended server, thus posing a significant risk to data integrity and confidentiality.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.