tamirverthim / src

Public git conversion mirror of OpenBSD's official cvs src repository.
https://www.openbsd.org
0 stars 0 forks source link

CVE-2021-46880 (High) detected in src0aecda14650f9fce8577e43d2a403385b5fa5bcf #71

Open mend-for-github-com[bot] opened 1 year ago

mend-for-github-com[bot] commented 1 year ago

CVE-2021-46880 - High Severity Vulnerability

Vulnerable Library - src0aecda14650f9fce8577e43d2a403385b5fa5bcf

Public git conversion mirror of OpenBSD's official CVS src repository. Pull requests not accepted - send diffs to the tech@ mailing list.

Library home page: https://github.com/openbsd/src.git

Vulnerable Source Files (2)

/lib/libcrypto/x509/x509_vfy.c /lib/libcrypto/x509/x509_vfy.c

Vulnerability Details

x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.

Publish Date: 2023-04-15

URL: CVE-2021-46880

CVSS 3 Score Details (9.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.