Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40810
HistoryJun 06, 2023 - 4:56 p.m.

Improper Certificate Validation

2023-06-0616:56:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
certificate validation
tls server certificates
subject alternative name
vulnerability
wildcard patterns
mismatched

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

0.002 Low

EPSS

Percentile

56.6%

curl is vulnerable to Improper Certificate Validation. The vulnerability allows matching of wildcard patterns when listed as ‘Subject Alternative Name’ in TLS server certificates and could result in accepting patterns that otherwise should be mismatched.

References

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

0.002 Low

EPSS

Percentile

56.6%