Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12214
HistoryJan 15, 2019 - 9:14 a.m.

TLS Session Resumption Client Certificate Bypass

2019-01-1509:14:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.004 Low

EPSS

Percentile

72.1%

libcurl.so is vulnerable to TLS session resumption client certificate bypass attacks. The vulnerability exists in Curl_clone_ssl_config of lib/vtls/vtls.c where libcurl.so does not prevent the TLS session resumption if the client certificate has been replaced.