Related Vulnerabilities: CVE-2021-3601  

OpenSSL 1.0.2 will accept a certificate with explicitly set Basic Constraints to CA:FALSE as a valid CA if it is present in the trusted bundle.

Severity Low

Remote Yes

Type Insufficient validation

Description

OpenSSL 1.0.2 will accept a certificate with explicitly set Basic Constraints to CA:FALSE as a valid CA if it is present in the trusted bundle.

AVG-1336 openssl-1.0 1.0.2.u-1 High Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1970201
https://github.com/openssl/openssl/issues/5236