Uploaded image for project: 'MariaDB Connector/node.js'
  1. MariaDB Connector/node.js
  2. CONJS-349

Cleartext password disclosure to MitM via mysql_clear_password

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • None
    • 3.4.6, 3.5.3, 3.3.3
    • other
    • None

    Description

      When an application connects with ssl: true (certificate verification ON) and a password, but does not pin a CA, the connector intentionally accepts an untrusted/self-signed server certificate at the TLS layer and instead proves the server's identity afterwards by binding the certificate fingerprint into the authentication exchange

      This delayed fingerprint/identity guard result in a Error thrown, but still might have been send to rogue server.

      Attachments

        Activity

          People

            diego dupin Diego Dupin
            diego dupin Diego Dupin
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.