Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38115
HistoryNov 19, 2022 - 6:50 p.m.

Improper Certification Validation

2022-11-1918:50:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4
firefox
certificate validation
vulnerability
tls connection
arbitrary certificates
software

0.001 Low

EPSS

Percentile

33.1%

firefox is vulnerable to improper certificate validation. The vulnerability exists because the certificates are not properly validated which allows an attacker to gain access to an ongoing TSL connection with the server sending arbitrary certificates.