Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7459-9rcq-g3xj

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.

The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.

EPSS

Процентиль: 76%
0.00983
Низкий

Связанные уязвимости

nvd
больше 21 года назад

The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.

EPSS

Процентиль: 76%
0.00983
Низкий