cesanta.mongoose is vulnerable to Improper Certificate Validation
74
High Risk
When the built-in TLS client is configured with a multi-certificate CA bundle, the topmost certificate of a presented chain is never cryptographically verified against a trust anchor. Trust validation degrades to comparing issuer and subject common-name strings, so a self-signed certificate naming a trusted root's common name is accepted. A network man-in-the-middle can fully impersonate the server, intercept traffic, and inject responses including firmware on devices that update over HTTP. The fix verifies the chain signature against the bundle anchor.
You are affected if you are using a version that falls within the vulnerable range and you use the built-in TLS backend (MG_TLS_BUILTIN) as a client configured with a multi-certificate CA bundle.
cesanta.mongoose is vulnerable to Improper Certificate Validation in versions 7.22 - 7.22.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant