Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
5.3.0 (semver) before 5.4.8
affected
Description
NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.
Problem types
CWE-295: Improper Certificate Validation
Product status
5.3.0 (semver) before 5.4.8
References
bugzilla.suse.com/show_bug.cgi?id=CVE-2025-66001
github.com/...vector/security/advisories/GHSA-4jj9-cgqc-x9h5