CVE Vulnerabilities

CVE-2022-37026

Published: Sep 21, 2022 | Modified: May 27, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
9.4 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

Affected Software

NameVendorStart VersionEnd Version
Erlang/otpErlang*23.3.4.15 (excluding)
Erlang/otpErlang24.0 (including)24.3.4.2 (excluding)
Erlang/otpErlang25.0 (including)25.0.2 (excluding)
Red Hat OpenStack Platform 16.2RedHaterlang-0:23.3.4.18-1.el8ost*
ErlangUbuntubionic*
ErlangUbuntudevel*
ErlangUbuntuesm-infra/focal*
ErlangUbuntufocal*
ErlangUbuntujammy*
ErlangUbuntukinetic*
ErlangUbuntulunar*
ErlangUbuntumantic*
ErlangUbuntunoble*
ErlangUbuntuoracular*
ErlangUbuntuplucky*
ErlangUbuntuquesting*
ErlangUbuntutrusty*
ErlangUbuntutrusty/esm*
ErlangUbuntuxenial*

References