Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw9p-3gc4-84rw

Опубликовано: 03 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection.  This has been corrected so that default certificates are no longer capable of overriding host name validation and will need to be replaced where full TLS certificate validation is needed for network security.  The existing certificates should be replaced with CA-signed certificates from a recognized certificate authority that contain the necessary information to support host name validation.

Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection.  This has been corrected so that default certificates are no longer capable of overriding host name validation and will need to be replaced where full TLS certificate validation is needed for network security.  The existing certificates should be replaced with CA-signed certificates from a recognized certificate authority that contain the necessary information to support host name validation.

EPSS

Процентиль: 11%
0.00037
Низкий

7.2 High

CVSS3

Дефекты

CWE-287
CWE-297

Связанные уязвимости

CVSS3: 7.2
nvd
больше 1 года назад

Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection.  This has been corrected so that default certificates are no longer capable of overriding host name validation and will need to be replaced where full TLS certificate validation is needed for network security.  The existing certificates should be replaced with CA-signed certificates from a recognized certificate authority that contain the necessary information to support host name validation.

EPSS

Процентиль: 11%
0.00037
Низкий

7.2 High

CVSS3

Дефекты

CWE-287
CWE-297