CVE Vulnerabilities

CVE-2022-37026

Published: Sep 21, 2022 | Modified: Aug 08, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
9.4 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Ubuntu
MEDIUM

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

Affected Software

Name Vendor Start Version End Version
Erlang/otp Erlang * 23.3.4.15 (excluding)
Erlang/otp Erlang 24.0 (including) 24.3.4.2 (excluding)
Erlang/otp Erlang 25.0 (including) 25.0.2 (excluding)
Red Hat OpenStack Platform 16.2 RedHat erlang-0:23.3.4.18-1.el8ost *
Erlang Ubuntu bionic *
Erlang Ubuntu devel *
Erlang Ubuntu focal *
Erlang Ubuntu jammy *
Erlang Ubuntu kinetic *
Erlang Ubuntu lunar *
Erlang Ubuntu mantic *
Erlang Ubuntu noble *
Erlang Ubuntu oracular *
Erlang Ubuntu trusty *
Erlang Ubuntu xenial *

References