Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade alpine | Aug 7, 2020 | Jun 19, 2020 |
| Debian | — | Upgrade alpine | Jun 29, 2020 | Jun 19, 2020 |
| Suse | — | Upgrade pilotUpgrade alpineUpgrade pico | May 7, 2021 | Jun 19, 2020 |
| Ubuntu | — | Upgrade alpine-pico (Ubuntu Pro)Upgrade alpine (Ubuntu Pro)Upgrade pilot (Ubuntu Pro) | Nov 19, 2024 | Jun 19, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub