Record summary

CVE-2016-10931 has a selected CVSS score of 8.1 (high).

Description

An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 0.9.0 · Fixed in 0.9.0affected

References

4