Cyberduck before 4.4.4 on Windows does not properly...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 20, 2025
Description
Published by the National Vulnerability Database
Nov 15, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Apr 20, 2025
Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL servers via a certificate issued by an arbitrary root Certification Authority.
References