Mbed-TLS.mbedtls is vulnerable to Improper Certificate Validation
65
Medium Risk
In TLS 1.2, an Mbed TLS client accepts any signature algorithm chosen by the server as long as it was enabled at compile time, even when the algorithm was not permitted by the policy configured with mbedtls_ssl_conf_sig_algs(). A server can therefore select a signature algorithm the client intended to forbid. This bypasses the client's configured signature-algorithm security policy. The fix makes the client reject server choices that fall outside the configured policy.
You are affected if you are using a version that falls within the vulnerable range and your TLS 1.2 client restricts signature algorithms with mbedtls_ssl_conf_sig_algs().
Mbed-TLS.mbedtls is vulnerable to Improper Certificate Validation in versions 3.3.0 - 3.6.5 and 4.0.0 - 4.0.0.
Upgrade the Mbed-TLS.mbedtls library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant