Description
MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate.
Affected products
- oracle / mysql_connector/net6.0.3
- oracle / mysql_connector/net6.0.0 – 6.0.0
- oracle / mysql_connector/net6.0.1 – 6.0.1
- oracle / mysql_connector/net6.0.2 – 6.0.2
Updated 16m ago · 8 sources