7.4

CVE-2021-3450

CA certificate check bypass with X509_V_FLAG_X509_STRICT

The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values implemented in libcrypto perform this check. Therefore, where a purpose is set the certificate chain will still be rejected even when the strict flag has been used. A purpose is set by default in libssl client and server certificate verification routines, but it can be overridden or removed by an application. In order to be affected, an application must explicitly set the X509_V_FLAG_X509_STRICT verification flag and either not set a purpose for the certificate verification or, in the case of TLS client or server applications, override the default purpose. OpenSSL versions 1.1.1h and newer are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1h-1.1.1j).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenSSL ≫ OpenSSL Version >= 1.1.1h < 1.1.1k
Freebsd ≫ Freebsd Version 12.2 Update -
Freebsd ≫ Freebsd Version 12.2 Update p1
Freebsd ≫ Freebsd Version 12.2 Update p2
Netapp ≫ Storagegrid Firmware Version -
   Netapp ≫ Storagegrid Version -
Windriver ≫ Linux Version - SwEdition cd
Windriver ≫ Linux Version 17.0 SwEdition lts
Windriver ≫ Linux Version 18.0 SwEdition lts
Windriver ≫ Linux Version 19.0 SwEdition lts
Netapp ≫ Storagegrid Version -
Fedoraproject ≫ Fedora Version 34
Tenable ≫ Nessus Version <= 8.13.1
Tenable ≫ Nessus Agent Version >= 8.2.1 <= 8.2.3
Tenable ≫ Nessus Network Monitor Version 5.11.0
Tenable ≫ Nessus Network Monitor Version 5.11.1
Tenable ≫ Nessus Network Monitor Version 5.12.0
Tenable ≫ Nessus Network Monitor Version 5.12.1
Tenable ≫ Nessus Network Monitor Version 5.13.0
Oracle ≫ Commerce Guided Search Version 11.3.2
Oracle ≫ Graalvm Version 19.3.5 SwEdition enterprise
Oracle ≫ Graalvm Version 20.3.1.2 SwEdition enterprise
Oracle ≫ Graalvm Version 21.0.0.2 SwEdition enterprise
Oracle ≫ Jd Edwards Enterpriseone Tools Version < 9.2.6.0
Oracle ≫ Mysql Connectors Version <= 8.0.23
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.23
Oracle ≫ Mysql Server Version <= 5.7.33
Oracle ≫ Mysql Server Version >= 8.0.15 <= 8.0.23
Oracle ≫ Mysql Workbench Version <= 8.0.23
Oracle ≫ Peoplesoft Enterprise Peopletools Version >= 8.57 <= 8.59
Oracle ≫ Secure Backup Version < 18.1.0.1.0
Oracle ≫ Secure Global Desktop Version 5.6
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
Mcafee ≫ Web Gateway Version 8.2.19
Mcafee ≫ Web Gateway Version 9.2.10
Mcafee ≫ Web Gateway Version 10.1.1
Mcafee ≫ Web Gateway Cloud Service Version 8.2.19
Mcafee ≫ Web Gateway Cloud Service Version 9.2.10
Mcafee ≫ Web Gateway Cloud Service Version 10.1.1
Sonicwall ≫ Sma100 Firmware Version < 10.2.1.0-17sv
   Sonicwall ≫ Sma100 Version -
Sonicwall ≫ Capture Client Version < 3.6.24
Sonicwall ≫ Email Security Version < 10.0.11
Sonicwall ≫ Sonicos Version <= 7.0.1-r1456
Nodejs ≫ Node.Js SwEdition - Version >= 10.0.0 < 10.24.1
Nodejs ≫ Node.Js SwEdition - Version >= 12.0.0 < 12.22.1
Nodejs ≫ Node.Js SwEdition - Version >= 14.0.0 < 14.16.1
Nodejs ≫ Node.Js SwEdition - Version >= 15.0.0 < 15.14.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 18.34% 0.969
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Patch
Third Party Advisory
https://www.tenable.com/security/tns-2021-08
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
Third Party Advisory
https://www.tenable.com/security/tns-2021-09
Third Party Advisory
https://security.gentoo.org/glsa/202103-03
Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10356
Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/03/27/1
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2021/03/27/2
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2021/03/28/3
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2021/03/28/4
Third Party Advisory
Mailing List
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013
Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.asc
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210326-0006/
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
Third Party Advisory
https://www.openssl.org/news/secadv/20210325.txt
Vendor Advisory
https://www.tenable.com/security/tns-2021-05
Third Party Advisory
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2a40b7bc7b94dd7de897a74571e7024f0cf0d63b
https://mta.openssl.org/pipermail/openssl-announce/2021-March/000198.html
Vendor Advisory
Mailing List