Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9fj-rcg9-g5cf

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.

The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.

EPSS

Процентиль: 39%
0.00173
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-295

Связанные уязвимости

CVSS3: 5.9
nvd
больше 14 лет назад

The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.

EPSS

Процентиль: 39%
0.00173
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-295