Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40018
HistoryApr 02, 2023 - 10:15 a.m.

Authorization Bypass

2023-04-0210:15:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
26
vulnerability
openssl
certificate verification
x509_verify_param_add0_policy
authorization bypass

EPSS

0.002

Percentile

55.1%

openssl is vulnerable to Authorization Bypasses. X509_VERIFY_PARAM_add0_policy() allows certificates with invalid or incorrect policies to pass certificate verification, but is disabled by default in OpenSSL and not commonly used by applications.