Pluto TLS Session Integrity Vulnerability
CVE-2024-32973
4.8MEDIUM
What is CVE-2024-32973?
In specific versions of Pluto, an active network attacker can exploit a vulnerability by using a specially crafted certificate to manipulate the trust decisions made by the Pluto language interpreter during TLS sessions. This could lead to an unexpected reduction in transport integrity for communications, specifically affecting the HTTP library and socket.starttls functionalities. A fix has been implemented in version 0.9.3, and users are strongly recommended to upgrade as no workarounds are available.
Affected Version(s)
Pluto >= 0.9.0, < 0.9.3