PT-2022-6116 · Owasp · Owasp Zed Attack Proxy
Gabriel Corona
·
Published
2022-03-24
·
Updated
2022-03-31
·
CVE-2022-27820
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OWASP Zed Attack Proxy versions through w2022-03-21
Description
The issue is related to incorrect authentication of a certificate in the web application security scanner. It may allow a remote attacker to compromise the integrity of protected information. The problem lies in the failure to verify the TLS certificate chain of an HTTPS server.
Recommendations
For OWASP Zed Attack Proxy versions through w2022-03-21, update to a version that verifies the TLS certificate chain of an HTTPS server to prevent exploitation. As a temporary workaround, consider restricting the use of the scanner until a patch is available.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Owasp Zed Attack Proxy