Home
MEDIUM: 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
3.9.10 (semver)
affected
Description
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted.
Problem types
CWE-295 Improper Certificate Validation
Product status
3.9.10 (semver)
Credits
d0sf3t (Aradex)
References
github.com/wolfSSL/wolfssl/pull/10223
www.wolfssl.com/docs/security-vulnerabilities/