Domain Validation Bypass Leading to Unauthorized TLS Certificate Issuance in SSL.com
SSL.com prior to 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requester's email address, even when the requester does not otherwise establish administrative control of that domain.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ssl.com ssl.com |