CWE-298
7 CVEs • Abstraction: Variant • Likelihood of Exploit: Low
Improper Validation of Certificate Expiration
A certificate expiration is not validated or is incorrectly validated, so trust may be assigned to certificates that have been abandoned due to age.
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wso2 5Api Manager Identity ServerIdentity Server As Key Manager+2 moreJul 9, 2026 Jul 4, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. Thi...Show more |
1Eclipse 1Cyclone Data Distribution Service Jul 5, 2026 Dec 23, 2025 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges. |
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections. |
Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the certificate expires. |
Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid....Show more |
The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The...Show more |
Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as...Show more |