Skip to content

Fix three high-severity authentication bypasses#59

Open
thistehneisen wants to merge 1 commit into
SK-EID:masterfrom
thistehneisen:security/cve-fix-validator
Open

Fix three high-severity authentication bypasses#59
thistehneisen wants to merge 1 commit into
SK-EID:masterfrom
thistehneisen:security/cve-fix-validator

Conversation

@thistehneisen
Copy link
Copy Markdown

See commit message; regression tests included.

- Cert-level downgrade (CVSS 7.4): derive level from policy OIDs, not JSON
- Web2App callback binding (CVSS 7.4): enforce binding inside validate()
- Trust anchor mis-classification (CVSS 7.5): reject non-CA PEMs at boundary

OffSeq Cybersecurity
https://offseq.com / https://radar.offseq.com
Nils Putnins / npu@offseq.com
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant