← Back

CVE-2021-3450

nvd nist
Published: Mar 25, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values implemented in libcrypto perform this check. Therefore, where a purpose is set the certificate chain will still be rejected even when the strict flag has been used. A purpose is set by default in libssl client and server certificate verification routines, but it can be overridden or removed by an application. In order to be affected, an application must explicitly set the X509_V_FLAG_X509_STRICT verification flag and either not set a purpose for the certificate verification or, in the case of TLS client or server applications, override the default purpose. OpenSSL versions 1.1.1h and newer are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1h-1.1.1j).

Affected (53)

Show all products
1 product
Openssl
1 product
Freebsd
6 products
Storagegrid Firmware
Cloud Volumes Ontap Mediator
Oncommand Workflow Automation
Storagegrid
1 product
Linux
1 product
Fedora
3 products
Nessus
Nessus Agent
Nessus Network Monitor
13 products
Commerce Guided Search
Graalvm
Jd Edwards Enterpriseone Tools
Jd Edwards World Security
Mysql Connectors
Mysql Enterprise Monitor
Mysql Server
Mysql Workbench
Peoplesoft Enterprise Peopletools
Secure Backup
Secure Global Desktop
Weblogic Server
2 products
Web Gateway
Web Gateway Cloud Service
4 products
Sma100 Firmware
Capture Client
Email Security
Sonicos
1 product
Node.js
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.1.1h to 1.1.1k
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 12.2
Version 12.2 p1
Version 12.2 p2
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Santricity Smi S Provider
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Storagegrid
All versions
Configuration E
4 vulnerable
Vulnerable SoftwareAffected Versions
Windriver
All versions
Version 17.0
Version 18.0
Version 19.0
Configuration F
4 vulnerable
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 34
Configuration H
7 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.13.1
From 8.2.1 to 8.2.3
Tenable
Version 5.11.0
Version 5.11.1
Version 5.12.0
Version 5.12.1
Version 5.13.0
Configuration I
17 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3.2
Version 13.4.0.0
Oracle
Version 19.3.5
Version 20.3.1.2
Version 21.0.0.2
Before 9.2.6.0
Version a9.4
Up to 8.0.23
Up to 8.0.23
Oracle
Up to 5.7.33
From 8.0.15 to 8.0.23
Up to 8.0.23
From 8.57 to 8.59
Before 18.1.0.1.0
Version 5.6
Oracle
Version 12.2.1.4.0
Version 14.1.1.0.0
Configuration J
6 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
Version 10.1.1
Version 8.2.19
Version 9.2.10
Mcafee
Version 10.1.1
Version 8.2.19
Version 9.2.10
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 10.2.1.0-17sv
Running on/withPlatform Versions
Sonicwall
Sma100
All versions
Configuration L
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.6.24
Before 10.0.11
Up to 7.0.1-r1456
Configuration M
4 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 10.0.0 to 10.24.1
From 12.0.0 to 12.22.1
From 14.0.0 to 14.16.1
From 15.0.0 to 15.14.0

References (48)

Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Mailing ListVendor Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Vendor Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.