Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g6x8-5jj7-qqfv

Опубликовано: 19 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.2

Описание

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

EPSS

Процентиль: 13%
0.00222
Низкий

9.2 Critical

CVSS4

Дефекты

CWE-295

Связанные уязвимости

ubuntu
около 1 года назад

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

nvd
около 1 года назад

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

msrc
12 месяцев назад

Domain Name Validation Bypass with Apple Native Certificate Validation

debian
около 1 года назад

A certificate verification error in wolfSSL when building with the WOL ...

EPSS

Процентиль: 13%
0.00222
Низкий

9.2 Critical

CVSS4

Дефекты

CWE-295