CVE-2020-15719
Severity
4.2MEDIUM
EPSS
0.2%
top 55.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 14
Latest updateMay 24
Description
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5
Affected Packages4 packages
Also affects: Enterprise Linux 8.0
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-pg7h-v386-fw8h: libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support↗2022-05-24
OSV▶
CVE-2020-15719: libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support↗2020-07-14
CVEList▶
CVE-2020-15719: libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support↗2020-07-14
📋Vendor Advisories
2💬Community
1Bugzilla
▶