VDB
Sign up
MEDIUM5.3

GHSA-jqqr-c2r2-9cvr

Improper Certificate Validation in security-framework

Details

If custom root certificates were registered with a ClientBuilder, the hostname of the target server would not be validated against its presented leaf certificate. This issue was fixed by properly configuring the trust evaluation logic to perform that check.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/security-framework
Introduced in: 0Fixed in: 0.1.12

Upgrade security-framework to 0.1.12 or newer (ecosystem crates.io).

References