An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Security-framework | Security-framework_project | * | 0.1.12 (excluding) |
Rust-security-framework-sys | Ubuntu | trusty | * |