When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
References
| Link | Resource |
|---|---|
| https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf | Exploit Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2025/03/msg00007.html | Mailing List Third Party Advisory |
| https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-02-26 22:15
Updated : 2025-04-07 18:39
NVD link : CVE-2024-55581
Mitre link : CVE-2024-55581
CVE.ORG link : CVE-2024-55581
JSON object : View
Products Affected
debian
- debian_linux
adacore
- ada_web_server
CWE
CWE-295
Improper Certificate Validation
