Skip to content

osquery does not validate TLS SNI hostname

Low
directionless published GHSA-pjmv-4494-jx3f Jul 10, 2020

Package

No package listed

Affected versions

< 4.2.0

Patched versions

4.2.0

Description

Impact

Because osquery does not correctly verify the TLS SNI hostname, it may be possible to present a valid certificate for a different TLS endpoint and, in the absence of a configured root chain of trust in osquery, MitM osquery traffic.

Patches

This was fixed in #6197

References

See the issue and discussion #6212

Severity

Low

CVE ID

CVE-2020-1887

Weaknesses

No CWEs