漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ssl fails to validate incorrect extened key usage
Vulnerability Description
OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP starting at OTP-25.3.2.8, OTP-26.2, and OTP-27.0, resulting in a server or client verifying the peer when incorrect extended key usage is presented (i.e., a server will verify a client if they have server auth ext key usage and vice versa).
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
Vulnerability Type
证书验证不恰当
Vulnerability Title
Erlang/OTP 信任管理问题漏洞
Vulnerability Description
Erlang/OTP是Erlang/OTP开源的一个JavaScript编写的处理处理异常的库。该库可以捕捉node.js内置API引发的异常。 Erlang/OTP OTP-25.3.2.8版本、OTP-26.2版本和OTP-27.0版本存在信任管理问题漏洞,该漏洞源于SSL应用程序引入了回归,导致服务器或客户端在出现不正确的扩展密钥用法时验证对等方。
CVSS Information
N/A
Vulnerability Type
N/A