CWE-295 · 1.502 kayıt
Hatalı sertifika doğrulama
Neden olur?
Sertifika doğrulama hatası, bağlantıyı kesmek yerine sessizce yutuluyor. Çoğu zaman test ortamı için eklenen kod üretime taşınır.
Hatalı ve düzeltilmiş kod
Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.
Hatalı
override fun checkServerTrusted(chain: Array<X509Certificate>, type: String) { // Test ortamı için boş bırakıldı}Düzeltilmiş
val client = OkHttpClient.Builder() .certificatePinner( CertificatePinner.Builder() .add("api.sirius.example", "sha256/…") .build() ).build()Nasıl önlenir?
- 01Platformun varsayılan güven zincirini değiştirmeyin.
- 02Kritik uygulamalarda sertifika sabitleme kullanın.
- 03Test yapılandırmalarının üretim derlemesine girmesini engelleyin.
Bu sınıftaki CVE’ler
1.504 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2022-26923Silahlaştırılmış | Active Directory Domain Services Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-295 | Yüksek8,8 | KEV | %83,5 | 10 May 2022 |
89Hemen | CVE-2020-0601Silahlaştırılmış | A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacmicrosoft · windows 10 1507 · CWE-295 | Yüksek8,1 | KEV | %89,4 | 14 Oca 2020 |
71Bu hafta | CVE-2026-85102Silahlaştırılmış | Improper Certificate Validation in Quantum Security Gatewaycheckpoint · gaia embedded · CWE-295 | Kritik9,8 | KEV | %7,5 | 9 Eyl 2026 |
65Bu hafta | CVE-2009-3555Kavram kanıtı | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Kritik9,8 | — | %87,3 | 9 Kas 2009 |
61Bu hafta | CVE-2023-20963Silahlaştırılmış | In WorkSource, there is a possible parcel mismatch.google · android · CWE-295 | Yüksek7,8 | KEV | %1,5 | 24 Mar 2023 |
56Planlayın | CVE-2023-41991Silahlaştırılmış | A certificate validation issue was addressed.apple · ipados · CWE-295 | Orta5,5 | KEV | %13,4 | 21 Eyl 2023 |
42Planlayın | CVE-2022-42979İstismar yok | Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take ovrydesharing · ryde · CWE-295 | Yüksek8,8 | — | %24,3 | 6 Oca 2023 |
42Planlayın | CVE-2017-2800Kavram kanıtı | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certifwolfssl · wolfssl · CWE-295 | Kritik9,8 | — | %8,5 | 24 May 2017 |
41Planlayın | CVE-2018-12829İstismar yok | Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability.adobe · creative cloud · CWE-295 | Kritik9,8 | — | %5,1 | 29 Ağu 2018 |
40Planlayın | CVE-2018-4991İstismar yok | Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability.adobe · creative cloud · CWE-295 | Kritik9,8 | — | %4,0 | 19 May 2018 |
40Planlayın | CVE-2015-2320İstismar yok | The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.mono-project · mono · CWE-295 | Kritik9,8 | — | %3,5 | 8 Oca 2018 |
40Planlayın | CVE-2020-28907İstismar yok | Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via venagios · fusion · CWE-295 | Kritik9,8 | — | %3,4 | 24 May 2021 |
40Planlayın | CVE-2018-21029İstismar yok | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.systemd project · systemd · CWE-295 | Kritik9,8 | — | %3,1 | 30 Eki 2019 |
40Planlayın | CVE-2021-33907İstismar yok | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .mzoom · meetings · CWE-295 | Kritik9,8 | — | %3,0 | 27 Eyl 2021 |
40Planlayın | CVE-2024-49369Kavram kanıtı | Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connectionsicinga · icinga · CWE-295 | Kritik9,8 | — | %2,9 | 12 Kas 2024 |
40Planlayın | CVE-2020-1952İstismar yok | An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.apache · iotdb · CWE-295 | Kritik9,8 | — | %2,7 | 27 Nis 2020 |
40Planlayın | CVE-2021-43882İstismar yok | Microsoft Defender for IoT Remote Code Execution Vulnerabilitymicrosoft · defender for iot · CWE-295 | Kritik9,8 | — | %2,4 | 15 Ara 2021 |
40Planlayın | CVE-2023-26463İstismar yok | strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes witstrongswan · strongswan · CWE-295 | Kritik9,8 | — | %2,3 | 14 Nis 2023 |
40Planlayın | CVE-2019-18847İstismar yok | Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.akamai · enterprise application access · CWE-295 | Kritik9,8 | — | %2,3 | 26 Ağu 2020 |
40Planlayın | CVE-2019-3777İstismar yok | Apps Manager unverified SSL certs in Cloud Controller proxypivotal software · application service · CWE-295 | Kritik9,8 | — | %1,9 | 7 Mar 2019 |
40Planlayın | CVE-2016-1000030İstismar yok | Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutlpidgin · pidgin · CWE-295 | Kritik9,8 | — | %1,8 | 5 Eyl 2018 |
40Planlayın | CVE-2015-3886İstismar yok | libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown libinfinity project · libinfinity · CWE-295 | Kritik9,8 | — | %1,7 | 21 Tem 2017 |
40Planlayın | CVE-2025-68121İstismar yok | Unexpected session resumption in crypto/tlsgolang · go · CWE-295 | Kritik10,0 | — | %0,9 | 5 Şub 2026 |
40Planlayın | CVE-2024-5261İstismar yok | TLS certificate are not properly verified when utilizing LibreOfficeKitlibreoffice · libreoffice · CWE-295 | Kritik10,0 | — | %0,4 | 25 Haz 2024 |
40Planlayın | CVE-2026-4370İstismar yok | Improper TLS Client/Server authentication and certificate verification on Database Clustercanonical · juju · CWE-295 | Kritik10,0 | — | %0,4 | 1 Nis 2026 |
- CVE-2022-2692390Hemen
Active Directory Domain Services Elevation of Privilege Vulnerability
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %84microsoft · windows 10 150710 May 2022
- CVE-2020-060189Hemen
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attac
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %89microsoft · windows 10 150714 Oca 2020
- CVE-2026-8510271Bu hafta
Improper Certificate Validation in Quantum Security Gateway
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %8checkpoint · gaia embedded9 Eyl 2026
- CVE-2009-355565Bu hafta
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
KritikCVSS 9,8Kavram kanıtıEPSS %87apache · http server9 Kas 2009
- CVE-2023-2096361Bu hafta
In WorkSource, there is a possible parcel mismatch.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1google · android24 Mar 2023
- CVE-2023-4199156Planlayın
A certificate validation issue was addressed.
OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %13apple · ipados21 Eyl 2023
- CVE-2022-4297942Planlayın
Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take ov
YüksekCVSS 8,8İstismar yokEPSS %24rydesharing · ryde6 Oca 2023
- CVE-2017-280042Planlayın
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif
KritikCVSS 9,8Kavram kanıtıEPSS %9wolfssl · wolfssl24 May 2017
- CVE-2018-1282941Planlayın
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability.
KritikCVSS 9,8İstismar yokEPSS %5adobe · creative cloud29 Ağu 2018
- CVE-2018-499140Planlayın
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability.
KritikCVSS 9,8İstismar yokEPSS %4adobe · creative cloud19 May 2018
- CVE-2015-232040Planlayın
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
KritikCVSS 9,8İstismar yokEPSS %4mono-project · mono8 Oca 2018
- CVE-2020-2890740Planlayın
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via ve
KritikCVSS 9,8İstismar yokEPSS %3nagios · fusion24 May 2021
- CVE-2018-2102940Planlayın
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.
KritikCVSS 9,8İstismar yokEPSS %3systemd project · systemd30 Eki 2019
- CVE-2021-3390740Planlayın
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .m
KritikCVSS 9,8İstismar yokEPSS %3zoom · meetings27 Eyl 2021
- CVE-2024-4936940Planlayın
Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
KritikCVSS 9,8Kavram kanıtıEPSS %3icinga · icinga12 Kas 2024
- CVE-2020-195240Planlayın
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.
KritikCVSS 9,8İstismar yokEPSS %3apache · iotdb27 Nis 2020
- CVE-2021-4388240Planlayın
Microsoft Defender for IoT Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2microsoft · defender for iot15 Ara 2021
- CVE-2023-2646340Planlayın
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes wit
KritikCVSS 9,8İstismar yokEPSS %2strongswan · strongswan14 Nis 2023
- CVE-2019-1884740Planlayın
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
KritikCVSS 9,8İstismar yokEPSS %2akamai · enterprise application access26 Ağu 2020
- CVE-2019-377740Planlayın
Apps Manager unverified SSL certs in Cloud Controller proxy
KritikCVSS 9,8İstismar yokEPSS %2pivotal software · application service7 Mar 2019
- CVE-2016-100003040Planlayın
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutl
KritikCVSS 9,8İstismar yokEPSS %2pidgin · pidgin5 Eyl 2018
- CVE-2015-388640Planlayın
libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown
KritikCVSS 9,8İstismar yokEPSS %2libinfinity project · libinfinity21 Tem 2017
- CVE-2025-6812140Planlayın
Unexpected session resumption in crypto/tls
KritikCVSS 10,0İstismar yokEPSS %1golang · go5 Şub 2026
- CVE-2024-526140Planlayın
TLS certificate are not properly verified when utilizing LibreOfficeKit
KritikCVSS 10,0İstismar yokEPSS %0libreoffice · libreoffice25 Haz 2024
- CVE-2026-437040Planlayın
Improper TLS Client/Server authentication and certificate verification on Database Cluster
KritikCVSS 10,0İstismar yokEPSS %0canonical · juju1 Nis 2026