GHSA-xgv7-pqqh-h2w9
HIGHCVE-2009-4123A security problem involving peer certificate verification was found where failed verification silently did nothing, making affected applications vulnerable to attackers. Attackers could lead a client application to believe that a secure connection to a rogue SSL server is legitimate. Attackers could also penetrate client-validated SSL server applications with a dummy certificate.
- Affected
- < 0.6
- Fixed in
- 0.6
- Weakness
- CWE-295
- Published
- 2023-01-19
- Source
- github