PT-2017-15155 · Rust · Security-Framework
Publicado
2017-03-15
·
Atualizado
2021-08-25
·
CVE-2017-18588
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
security-framework crate versions prior to 0.1.12
Description
An issue was discovered where hostname verification for certificates does not occur if ClientBuilder uses custom root certificates. Specifically, if custom root certificates were registered with a
ClientBuilder, the hostname of the target server would not be validated against its presented leaf certificate. This issue was fixed by properly configuring the trust evaluation logic to perform that check.Recommendations
For security-framework crate versions prior to 0.1.12, update to version 0.1.12 or later to resolve the issue. As a temporary workaround, consider avoiding the use of custom root certificates with ClientBuilder until the update is applied.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Security-Framework