MEDIUM5.3
GHSA-jqqr-c2r2-9cvr
Improper Certificate Validation in security-framework
Details
If custom root certificates were registered with a ClientBuilder, the hostname of the target server would not be validated against its presented leaf certificate. This issue was fixed by properly configuring the trust evaluation logic to perform that check.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/security-framework
Introduced in:
0Fixed in: 0.1.12Upgrade security-framework to 0.1.12 or newer (ecosystem crates.io).