e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates of the web servers that it connected to, and thus was itself vulnerable to MITM attacks.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2021/12/23/2 | Mailing List Third Party Advisory |
https://github.com/e2guardian/e2guardian/commit/eae46a7e2a57103aadca903c4a24cca94dc502a2 | Patch Third Party Advisory |
https://github.com/e2guardian/e2guardian/issues/707 | Exploit Issue Tracking Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/09/msg00010.html | |
http://www.openwall.com/lists/oss-security/2021/12/23/2 | Mailing List Third Party Advisory |
https://github.com/e2guardian/e2guardian/commit/eae46a7e2a57103aadca903c4a24cca94dc502a2 | Patch Third Party Advisory |
https://github.com/e2guardian/e2guardian/issues/707 | Exploit Issue Tracking Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/09/msg00010.html |
Configurations
History
21 Nov 2024, 06:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2021/12/23/2 - Mailing List, Third Party Advisory | |
References | () https://github.com/e2guardian/e2guardian/commit/eae46a7e2a57103aadca903c4a24cca94dc502a2 - Patch, Third Party Advisory | |
References | () https://github.com/e2guardian/e2guardian/issues/707 - Exploit, Issue Tracking, Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/09/msg00010.html - |
13 Sep 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2021-12-23 12:15
Updated : 2024-11-21 06:30
NVD link : CVE-2021-44273
Mitre link : CVE-2021-44273
CVE.ORG link : CVE-2021-44273
JSON object : View
Products Affected
e2bn
- e2guardian
CWE
CWE-295
Improper Certificate Validation