CVE-2021-3450

Related Vulnerabilities: CVE-2021-3450  

A flaw was found in openssl. The flag that enables additional security checks of certificates present in a certificate chain was not enabled allowing a confirmation step to verify that certificates in the chain are valid CA certificates is bypassed. The highest threat from this vulnerability is to data confidentiality and integrity.

Description

A flaw was found in openssl. The flag that enables additional security checks of certificates present in a certificate chain was not enabled allowing a confirmation step to verify that certificates in the chain are valid CA certificates is bypassed. The highest threat from this vulnerability is to data confidentiality and integrity.

Statement

This flaw affects openssl 1.1.1h and above only, older versions are not affected by this flaw. OpenSSL internally and applications shipped with Red Hat Enterprise Linux compiled with OpenSSL do not use the X509_V_FLAG_X509_STRICT and therefore are not affected by this flaw.

This flaw affects openssl 1.1.1h and above only, older versions are not affected by this flaw. OpenSSL internally and applications shipped with Red Hat Enterprise Linux compiled with OpenSSL do not use the X509_V_FLAG_X509_STRICT and therefore are not affected by this flaw.

Additional Information

  • Bugzilla 1941547: CVE-2021-3450 openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT
  • CWE-295: Improper Certificate Validation
  • FAQ: Frequently asked questions about CVE-2021-3450