CVE-2019-5102: Medium severity open edx vulnerability
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5102?
CVE-2019-5102 is an exploitable information leak vulnerability in the ustream-ssl library of OpenWrt versions 18.06.4 and 15.05.1.
What is the severity of CVE-2019-5102?
The severity of CVE-2019-5102 is medium with a severity value of 5.9.
How does CVE-2019-5102 affect OpenWrt?
CVE-2019-5102 affects OpenWrt versions 18.06.4 and 15.05.1.
How can an attacker exploit CVE-2019-5102?
An attacker can exploit CVE-2019-5102 by exploiting the behavior of OpenWrt where the server's SSL certificate is checked but no action is taken when the certificate is invalid.
Is there a fix for CVE-2019-5102?
Yes, to fix CVE-2019-5102, users should update their OpenWrt installations to the latest available version.