← Back
CWE-298

7 CVEs • Abstraction: Variant • Likelihood of Exploit: Low

Improper Validation of Certificate Expiration

A certificate expiration is not validated or is incorrectly validated, so trust may be assigned to certificates that have been abandoned due to age.

JSON object

Loading...

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wso2
5Api Manager
Identity ServerIdentity Server As Key Manager+2 more
Jul 9, 2026
Jul 4, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. Thi...Show more
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.Show less
1Eclipse
1Cyclone Data Distribution Service
Jul 5, 2026
Dec 23, 2025
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
1Eprosima
1Fast Dds
Jul 5, 2026
Dec 23, 2025
N/A· v4
10.0 CRITICAL· v3
N/A· v2
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
-
-
Jun 17, 2026
Dec 17, 2025
7.1 HIGH· v4
N/A· v3
N/A· v2
Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the certificate expires.
-
-
Jun 17, 2026
Sep 9, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid....Show more
Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid. This means that any API token that is associated with an active user account can authenticate successfully. This issue is fixed in versions 1.3.9 and 1.4.5. As a workaround, users can delete or deactivate the account associated with a deleted API token to prevent that token from authenticating.Show less
-
-
Jun 17, 2026
May 6, 2025
6.0 MEDIUM· v4
N/A· v3
N/A· v2
The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The...Show more
The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random devices to take advantage of this flaw.Show less
1Powauth
1Pow
Jun 17, 2026
Sep 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as...Show more
Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on startup. A session may expire when all `Pow.Store.Backend.MnesiaCache` instances have been shut down for a period that is longer than a session's remaining TTL. Version 1.0.34 contains a patch for this issue. As a workaround, expired keys, including all expired sessions, can be manually invalidated.Show less