An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.