Cyberduck and Mountain Duck improper handle TLS...
High severity
Unreviewed
Published
Jun 26, 2025
to the GitHub Advisory Database
•
Updated Jun 26, 2025
Description
Published by the National Vulnerability Database
Jun 25, 2025
Published to the GitHub Advisory Database
Jun 26, 2025
Last updated
Jun 26, 2025
Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although SHA-1 is considered weak.
This issue affects Cyberduck: through 9.1.6; Mountain Duck: through 4.17.5.
References