Описание
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.1.12 (исключая)
cpe:2.3:a:security-framework_project:security-framework:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00104
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 5.3
ubuntu
больше 6 лет назад
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.
CVSS3: 5.3
debian
больше 6 лет назад
An issue was discovered in the security-framework crate before 0.1.12 ...
CVSS3: 5.3
github
больше 4 лет назад
Improper Certificate Validation in security-framework
EPSS
Процентиль: 29%
0.00104
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-295