← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Kubernetes
Redhat
2Kubernetes
Openshift
Nov 21, 2024
Sep 10, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by u...Show more
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.Show less
1Linecorp
1Line Music
Nov 21, 2024
Sep 7, 2018
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cr...Show more
The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Pulsesecure
1Pulse Secure Desktop Client
Nov 21, 2024
Sep 6, 2018
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.
1Dsub For Subsonic Project
1Dsub For Subsonic
Nov 21, 2024
Sep 6, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signe...Show more
daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signed and expired, are accepted by the client. This attack appear to be exploitable via The victim connects to a server that's MITM/Proxied by an attacker.Show less
2Pidgin
Suse
2Linux Enterprise Server
Pidgin
Nov 21, 2024
Sep 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution...Show more
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.Show less
1Mystrom
6Wifi Bulb Firmware
Wifi Button FirmwareWifi Button Plus Firmware+3 more
Nov 21, 2024
Aug 30, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus befo...Show more
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The SSL/TLS server certificate in the device to cloud communication was not verified by the device. As a result, an attacker in control of the network traffic of a device could have taken control of a device by intercepting and modifying commands issued from the server to the device in a Man-in-the-Middle attack. This included the ability to inject firmware update commands into the communication and cause the device to install maliciously modified firmware.Show less
1Adobe
1Creative Cloud
Nov 21, 2024
Aug 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to privilege escalation.
1Samsung
1Sth Eth 250 Firmware
Nov 21, 2024
Aug 27, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. When hubCore crashes, Google Breakpad is used t...Show more
An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. When hubCore crashes, Google Breakpad is used to record minidumps, which are sent over an insecure HTTPS connection to the backtrace.io service, leading to the exposure of sensitive data. An attacker can impersonate the remote backtrace.io server in order to trigger this vulnerability.Show less
1Redhat
1Satellite
Nov 21, 2024
Aug 22, 2018
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a Postgre...Show more
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.Show less
1Hisecuritylab
1Virus Cleaner
Nov 21, 2024
Aug 15, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Hi Security Virus Cleaner - Antivirus, Booster, 3.7.1.1329, 2017-09-13, Android application accepts all SSL certificates during SSL communication. This opens the application up to a man-in-the-middle attack having all of...Show more
Hi Security Virus Cleaner - Antivirus, Booster, 3.7.1.1329, 2017-09-13, Android application accepts all SSL certificates during SSL communication. This opens the application up to a man-in-the-middle attack having all of its encrypted traffic intercepted and read by an attacker.Show less
1Ibm
1Rational Clearquest
Nov 21, 2024
Aug 13, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an im...Show more
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an impersonating server observing all the data transmitted to the real server. IBM X-Force ID: 113353.Show less
4Apache
CanonicalDebian+1 more
4Debian Linux
Retail Order BrokerTomcat+1 more
Jun 17, 2026
Aug 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.8...Show more
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.Show less
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Aug 1, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
1Jenkins
1Inedo Buildmaster
Nov 21, 2024
Aug 1, 2018
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service...Show more
A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service that Jenkins connects to.Show less
1Jenkins
1Inedo Proget
Nov 21, 2024
Aug 1, 2018
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to impersonate any service that Jenkins connect...Show more
A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to impersonate any service that Jenkins connects to.Show less
1Jenkins
1Tracetronic Ecu Test
Nov 21, 2024
Aug 1, 2018
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any service that Jenkins connects to.
2Apache
Debian
2Debian Linux
Tomcat Native
Jun 17, 2026
Jul 31, 2018
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client cert...Show more
Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.Show less
2Apache
Debian
2Debian Linux
Tomcat Native
Jun 17, 2026
Jul 31, 2018
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefo...Show more
When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate with revoked certificates when using mutual TLS. Users not using OCSP checks are not affected by this vulnerability.Show less
1Jenkins
1Active Directory
Nov 21, 2024
Jul 27, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
1Jenkins
1Ssh Slaves
Nov 21, 2024
Jul 27, 2018
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.