Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-297 (对宿主不匹配的证书验证不恰当) — Vulnerability Class 35

35 vulnerabilities classified as CWE-297 (对宿主不匹配的证书验证不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-41603 Apache Thrift: Java TSSLTransportFactory hostname verification — Apache Thrift 7.5AIHighAI2026-04-28
CVE-2026-34477 Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass — Apache Log4j Core 8.2AIHighAI2026-04-10
CVE-2025-59060 Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient — Apache Ranger 5.3AIMediumAI2026-03-03
CVE-2026-26214 Xiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITM — Galaxy FDS Android SDK 7.4 High2026-02-12
CVE-2025-68637 Apache Uniffle: Insecure SSL Configuration in Uniffle HTTP Client — Apache Uniffle 5.9 -2026-01-07
CVE-2025-68161 Apache Log4j Core: Missing TLS hostname verification in Socket appender — Apache Log4j Core 7.4AIHighAI2025-12-18
CVE-2025-25253 Fortinet FortiOS和Fortinet FortiProxy 安全漏洞 — FortiProxy 6.8 High2025-10-14
CVE-2024-12925 Host Header Injection in Akinsoft's QR Menu — QR Menü 7.3 High2025-09-01
CVE-2025-4295 Host Header Injection in HotelRunner's B2B — B2B 4.6 Medium2025-07-22
CVE-2024-54019 Fortinet FortiClientWindows 安全漏洞 — FortiClientWindows 4.4 Medium2025-06-10
CVE-2025-3501 Org.keycloak.protocol.services: keycloak hostname verification 8.2 High2025-04-29
CVE-2025-42921 JetBrains Toolbox App 安全漏洞 — Toolbox App 4.2 Medium2025-04-17
CVE-2025-2190 TECNO com.transsnet.store 安全漏洞 — com.transsnet.store 8.1 -2025-03-11
CVE-2024-49782 IBM OpenPages improper certificate validation — OpenPages with Watson 6.8 Medium2025-02-20
CVE-2024-38324 IBM Storage Defender improper certificate validation — Storage Defender - Resiliency Service 5.9 Medium2024-09-24
CVE-2024-7346 Client connections using default TLS certificates from OpenEdge may bypass TLS host name validation — OpenEdge 7.2 High2024-09-03
CVE-2024-8285 Kroxylicious: missing upstream kafka tls hostname verification 5.9 Medium2024-08-30
CVE-2024-2462 Hitachi FOXMAN-UN 安全漏洞 — FOXMAN-UN 9.1AICriticalAI2024-06-11
CVE-2023-5909 Improper Validation of Certificate with Host Mismatch in PTC KEPServerEx — KEPServerEX 7.5 High2023-11-30
CVE-2022-22305 多款Fortinet产品信任管理问题漏洞 — FortiAnalyzer 5.4 Medium2023-09-01
CVE-2023-34143 Improper Validation of Certificate Vulnerability in Hitachi Device Manager — Hitachi Device Manager 5.6 Medium2023-07-18
CVE-2023-24568 Dell NetWorker 信任管理问题漏洞 — NetWorker 5.0 Medium2023-05-30
CVE-2022-48308 Palantir 信任管理问题漏洞 — sls-logging 6.3 Medium2023-02-16
CVE-2022-48307 Palantir 信任管理问题漏洞 — Foundry Magritte 6.3 Medium2023-02-16
CVE-2022-48306 Gotham Chat IRC help does not validate hostnames in TLS certificates — Palantir Gotham Chat IRC helper 5.7 Medium2023-02-16
CVE-2022-27890 Palantir 信任管理问题漏洞 — AtlasDB 6.3 Medium2023-02-16
CVE-2022-32153 Splunk Enterprise lacked TLS host name validation — Splunk Enterprise 8.1 High2022-06-15
CVE-2022-29082 DELL EMC NetWorker 信任管理问题漏洞 — NetWorker 3.7 Low2022-05-26
CVE-2021-33695 SAP ERP 信任管理问题漏洞 — SAP Cloud Connector 9.1 -2021-09-15
CVE-2020-14387 rsync rsync-ssl 存在安全漏洞 — rsync 7.4 -2021-05-27

Vulnerabilities classified as CWE-297 (对宿主不匹配的证书验证不恰当) represent 35 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.