SSL/TLS Man-in-the-Middle Vulnerability in OpenSSL for Rust
CVE-2016-10931
8.1HIGH
What is CVE-2016-10931?
A flaw in the OpenSSL crate prior to version 0.9.0 for Rust allows for man-in-the-middle attacks due to disabled default certificate verification. The absence of an API for hostname verification further exacerbates the issue, potentially allowing attackers to impersonate legitimate services without detection.
