CVE Vulnerabilities

CVE-2021-46880

Improper Certificate Validation

Published: Apr 15, 2023 | Modified: May 17, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Libressl Openbsd * 3.4.2 (excluding)
Openbsd Openbsd * 7.0 (excluding)

Potential Mitigations

References