systemd 239 through 243 accepts any certificate signed by...
Critical severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 30, 2024
Description
Published by the National Vulnerability Database
Oct 30, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Mar 30, 2024
systemd 239 through 243 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend.
References