Lucene search

K
redhatcveRedhat.comRH:CVE-2018-8020
HistoryAug 01, 2018 - 4:23 a.m.

CVE-2018-8020

2018-08-0104:23:38
redhat.com
access.redhat.com
19

0.012 Low

EPSS

Percentile

85.3%

When using pre-produced responses from an OCSP responder, Tomcat Native did not correctly validate the status of certificates. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate with revoked certificates when using mutual TLS.