A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4 | Range not provided by sourceCNA affecteddefault unknown | |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.