Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7840
HistoryNov 19, 2018 - 7:52 a.m.

Authentication Bypass

2018-11-1907:52:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.008 Low

EPSS

Percentile

81.8%

openssl is vulnerable to an authentication bypass. The library does not properly compare OpenSSL::X509::Name objects, leading to non-equal objects to be returned as equal. This can allow a malicious user to pass a spoofed certificate to the system during the authentication process.

References