CVE-2020-14929

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
Configurations

Configuration 1 (hide)

cpe:2.3:a:alpine_project:alpine:*:*:*:*:*:*:*:*

Information

Published : 2020-06-19 19:15

Updated : 2020-07-03 04:15


NVD link : CVE-2020-14929

Mitre link : CVE-2020-14929


JSON object : View

Products Affected

alpine_project

  • alpine
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor