4
CVSSv2

CVE-2022-28352

Published: 02/04/2022 Updated: 13/04/2022
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 4.8 | Impact Score: 2.5 | Exploitability Score: 2.2
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 prior to 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which allows man-in-the-middle malicious users to spoof a TLS chat server via an arbitrary certificate. NOTE: this only affects situations where weechat.network.gnutls_ca_system or weechat.network.gnutls_ca_user is changed without a WeeChat restart.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

weechat weechat