Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46220
HistoryApr 05, 2024 - 2:09 a.m.

TLS Certificate Check Bypass

2024-04-0502:09:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
vulnerability
tls certificate
libcurl
mbedtls
ip address
certificate check
https
ftps
imaps
pops3
smtps

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

libcurl is vulnerable to TLS Certificate Check Bypass. The vulnerability is caused due to libcurl not checking the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address. This leads to completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%