Описание
The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.
Ссылки
- Third Party Advisory
- ProductVendor Advisory
- Third Party Advisory
- ProductVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1 (исключая)
cpe:2.3:a:europa:technical_specifications_for_digital_covid_certificates:*:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00265
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-295
EPSS
Процентиль: 50%
0.00265
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-295