Описание
In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).
EPSS
Процентиль: 13%
0.00225
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 9.1
debian
около 2 месяцев назад
In OCaml-TLS before 2.1.0, the client implementation does insufficient ...
CVSS3: 9.1
github
около 2 месяцев назад
In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).
EPSS
Процентиль: 13%
0.00225
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-295