CVE-2016-10932
HTTPS MitM vulnerability due to lack of hostname verification
4.8
MEDIUM
CVSS 3.1
EPSS 0.74%
Description
When used on Windows platforms, all versions of Hyper prior to 0.9.4 did not perform hostname verification when making HTTPS requests. This allows an attacker to perform MitM attacks by preventing any valid CA-issued certificate, even if there's a hostname mismatch. The problem was addressed by leveraging rust-openssl's built-in support for hostname verification.
How to fix CVE-2016-10932
To remediate CVE-2016-10932, upgrade the affected package to a fixed version below.
- —upgrade to 0.9.4 or later
- —upgrade to 0.9.4 or later
Is CVE-2016-10932 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.9.4
- >= 0.0.0-0, < 0.9.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.8 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |