CVE Vulnerabilities

CVE-2024-48460

Improper Certificate Validation

Published: Jan 16, 2025 | Modified: Feb 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References