CVE-2024-55581: High severity ada web server vulnerability
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55581?
CVE-2024-55581 has a high severity due to its potential for man-in-the-middle attacks.
How do I fix CVE-2024-55581?
To fix CVE-2024-55581, ensure that your program specifies a proper TLS configuration to enforce certificate verification.
Which versions are affected by CVE-2024-55581?
CVE-2024-55581 affects AdaCore Ada Web Server version 25.0.0 when linked with GnuTLS.
What kind of attack does CVE-2024-55581 expose users to?
CVE-2024-55581 exposes users to man-in-the-middle attacks due to a lack of HTTPS server certificate verification.
What software is involved in CVE-2024-55581?
CVE-2024-55581 involves AdaCore Ada Web Server and GnuTLS when they are improperly configured.