Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqqr-c2r2-9cvr

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper Certificate Validation in security-framework

If custom root certificates were registered with a ClientBuilder, the hostname of the target server would not be validated against its presented leaf certificate. This issue was fixed by properly configuring the trust evaluation logic to perform that check.

Пакеты

Наименование

security-framework

rust
Затронутые версииВерсия исправления

< 0.1.12

0.1.12

EPSS

Процентиль: 29%
0.00104
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.

CVSS3: 5.3
nvd
больше 6 лет назад

An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.

CVSS3: 5.3
debian
больше 6 лет назад

An issue was discovered in the security-framework crate before 0.1.12 ...

EPSS

Процентиль: 29%
0.00104
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295