Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48jg-h3cv-mqvx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.

EPSS

Процентиль: 15%
0.00048
Низкий

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.

EPSS

Процентиль: 15%
0.00048
Низкий

Дефекты

CWE-347