Описание
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted.
Ссылки
- Issue TrackingPatch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.9.10 (включая) до 5.9.2 (исключая)
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*
EPSS
Процентиль: 3%
0.00124
Низкий
7.5 High
CVSS3
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 1 месяца назад
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted.
CVSS3: 7.5
debian
около 1 месяца назад
X.509 name constraint bypass via the Subject Common Name when treated ...
CVSS3: 7.5
github
около 1 месяца назад
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted.
EPSS
Процентиль: 3%
0.00124
Низкий
7.5 High
CVSS3
Дефекты
CWE-295