AdaCore/aws

AdaCore/aws

Releases54
Frequency4 months 3 weeks
Last Release
Stars158
AWS is a complete framework to develop Web based applications in Ada.

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.

7.4 HIGH

An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.