Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-48437


An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificate.


Published

2023-04-12T05:15:07.653

Last Modified

2025-02-10T17:15:15.690

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-295
  • Type: Secondary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openbsd libressl < 3.6.1 Yes
Operating System openbsd openbsd < 7.2 Yes

References