Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g6x8-5jj7-qqfv

Опубликовано: 19 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.2

Описание

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

EPSS

Процентиль: 8%
0.00033
Низкий

9.2 Critical

CVSS4

Дефекты

CWE-295

Связанные уязвимости

ubuntu
около 1 месяца назад

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

nvd
около 1 месяца назад

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

debian
около 1 месяца назад

A certificate verification error in wolfSSL when building with the WOL ...

EPSS

Процентиль: 8%
0.00033
Низкий

9.2 Critical

CVSS4

Дефекты

CWE-295