wolfSSL.wolfssl is vulnerable to Inadequate Encryption Strength
63
Medium Risk
With TLS 1.3 pre-shared keys (PSK), a malicious or faulty server could ignore the client’s request for perfect forward secrecy (PFS) and still establish a PSK connection without PFS. This occurs when the server responds to a ClientHello containing psk_dhe_ke without including a key_share extension. As a result, the client may unknowingly reuse an authenticated PSK connection without PFS, reducing the overall security of the connection.
You are affected if you are using a version that falls within the vulnerable range.
wolfSSL.wolfssl is vulnerable to Inadequate Encryption Strength in versions 5.8.2 - 5.8.2.
Upgrade the wolfSSL.wolfssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant