When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf | vendor advisory exploit |
https://lists.debian.org/debian-lts-announce/2025/03/msg00007.html | mailing list third party advisory |