CVE Vulnerabilities

CVE-2022-28352

Improper Certificate Validation

Published: Apr 02, 2022 | Modified: Apr 13, 2022
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which allows man-in-the-middle attackers to spoof a TLS chat server via an arbitrary certificate. NOTE: this only affects situations where weechat.network.gnutls_ca_system or weechat.network.gnutls_ca_user is changed without a WeeChat restart.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Weechat Weechat 3.2 (including) 3.4.1 (excluding)
Weechat Ubuntu bionic *
Weechat Ubuntu impish *
Weechat Ubuntu kinetic *
Weechat Ubuntu trusty *
Weechat Ubuntu upstream *
Weechat Ubuntu xenial *

Potential Mitigations

References