İçeriğe atla
Noroxi

CWE-295 · 1.502 kayıt

Hatalı sertifika doğrulama

Neden olur?

Sertifika doğrulama hatası, bağlantıyı kesmek yerine sessizce yutuluyor. Çoğu zaman test ortamı için eklenen kod üretime taşınır.

Hatalı ve düzeltilmiş kod

Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.

Hatalı

kotlin
override fun checkServerTrusted(chain: Array<X509Certificate>, type: String) {  // Test ortamı için boş bırakıldı}

Düzeltilmiş

kotlin
val client = OkHttpClient.Builder()  .certificatePinner(    CertificatePinner.Builder()      .add("api.sirius.example", "sha256/…")      .build()  ).build()

Nasıl önlenir?

  1. 01Platformun varsayılan güven zincirini değiştirmeyin.
  2. 02Kritik uygulamalarda sertifika sabitleme kullanın.
  3. 03Test yapılandırmalarının üretim derlemesine girmesini engelleyin.

Bu sınıftaki CVE’ler

1.504 kayıt

  • Active Directory Domain Services Elevation of Privilege Vulnerability

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %84

    microsoft · windows 10 150710 May 2022

  • A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attac

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %89

    microsoft · windows 10 150714 Oca 2020

  • CVE-2026-85102
    71Bu hafta

    Improper Certificate Validation in Quantum Security Gateway

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %8

    checkpoint · gaia embedded9 Eyl 2026

  • CVE-2009-3555
    65Bu hafta

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th

    KritikCVSS 9,8Kavram kanıtıEPSS %87

    apache · http server9 Kas 2009

  • CVE-2023-20963
    61Bu hafta

    In WorkSource, there is a possible parcel mismatch.

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1

    google · android24 Mar 2023

  • CVE-2023-41991
    56Planlayın

    A certificate validation issue was addressed.

    OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %13

    apple · ipados21 Eyl 2023

  • CVE-2022-42979
    42Planlayın

    Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take ov

    YüksekCVSS 8,8İstismar yokEPSS %24

    rydesharing · ryde6 Oca 2023

  • CVE-2017-2800
    42Planlayın

    A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    wolfssl · wolfssl24 May 2017

  • CVE-2018-12829
    41Planlayın

    Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %5

    adobe · creative cloud29 Ağu 2018

  • CVE-2018-4991
    40Planlayın

    Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %4

    adobe · creative cloud19 May 2018

  • CVE-2015-2320
    40Planlayın

    The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

    KritikCVSS 9,8İstismar yokEPSS %4

    mono-project · mono8 Oca 2018

  • CVE-2020-28907
    40Planlayın

    Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via ve

    KritikCVSS 9,8İstismar yokEPSS %3

    nagios · fusion24 May 2021

  • CVE-2018-21029
    40Planlayın

    systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.

    KritikCVSS 9,8İstismar yokEPSS %3

    systemd project · systemd30 Eki 2019

  • CVE-2021-33907
    40Planlayın

    The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .m

    KritikCVSS 9,8İstismar yokEPSS %3

    zoom · meetings27 Eyl 2021

  • CVE-2024-49369
    40Planlayın

    Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    icinga · icinga12 Kas 2024

  • CVE-2020-1952
    40Planlayın

    An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.

    KritikCVSS 9,8İstismar yokEPSS %3

    apache · iotdb27 Nis 2020

  • CVE-2021-43882
    40Planlayın

    Microsoft Defender for IoT Remote Code Execution Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %2

    microsoft · defender for iot15 Ara 2021

  • CVE-2023-26463
    40Planlayın

    strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes wit

    KritikCVSS 9,8İstismar yokEPSS %2

    strongswan · strongswan14 Nis 2023

  • CVE-2019-18847
    40Planlayın

    Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.

    KritikCVSS 9,8İstismar yokEPSS %2

    akamai · enterprise application access26 Ağu 2020

  • CVE-2019-3777
    40Planlayın

    Apps Manager unverified SSL certs in Cloud Controller proxy

    KritikCVSS 9,8İstismar yokEPSS %2

    pivotal software · application service7 Mar 2019

  • CVE-2016-1000030
    40Planlayın

    Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutl

    KritikCVSS 9,8İstismar yokEPSS %2

    pidgin · pidgin5 Eyl 2018

  • CVE-2015-3886
    40Planlayın

    libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown

    KritikCVSS 9,8İstismar yokEPSS %2

    libinfinity project · libinfinity21 Tem 2017

  • CVE-2025-68121
    40Planlayın

    Unexpected session resumption in crypto/tls

    KritikCVSS 10,0İstismar yokEPSS %1

    golang · go5 Şub 2026

  • CVE-2024-5261
    40Planlayın

    TLS certificate are not properly verified when utilizing LibreOfficeKit

    KritikCVSS 10,0İstismar yokEPSS %0

    libreoffice · libreoffice25 Haz 2024

  • CVE-2026-4370
    40Planlayın

    Improper TLS Client/Server authentication and certificate verification on Database Cluster

    KritikCVSS 10,0İstismar yokEPSS %0

    canonical · juju1 Nis 2026

Tüm zafiyet sınıfları