PT-2022-6116 · Owasp · Owasp Zed Attack Proxy

Gabriel Corona

·

Published

2022-03-24

·

Updated

2022-03-31

·

CVE-2022-27820

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions OWASP Zed Attack Proxy versions through w2022-03-21
Description The issue is related to incorrect authentication of a certificate in the web application security scanner. It may allow a remote attacker to compromise the integrity of protected information. The problem lies in the failure to verify the TLS certificate chain of an HTTPS server.
Recommendations For OWASP Zed Attack Proxy versions through w2022-03-21, update to a version that verifies the TLS certificate chain of an HTTPS server to prevent exploitation. As a temporary workaround, consider restricting the use of the scanner until a patch is available.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00056
CVE-2022-27820
GHSA-J7XG-5549-JR3J

Affected Products

Owasp Zed Attack Proxy