mariadb is vulnerable to Improper Certificate Validation
80
High Risk
Affected versions of this package are vulnerable to improper certificate validation when connecting to a MariaDB server. Specifically, the servername parameter is not properly validated during the TLS handshake, resulting in a failure to verify the server's identity. This flaw allows attackers with a valid certificate for a different hostname to impersonate the server, potentially enabling man-in-the-middle (MITM) attacks.
You are affected if you are using a version that falls within the vulnerable range.
mariadb is vulnerable to Improper Certificate Validation in versions 0.0.1 - 3.4.2.
Upgrade the mariadb library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant