cesanta.mongoose is vulnerable to Improper Certificate Validation
74
High Risk
The built-in TLS client verifies certificate hostnames with a generic pattern matcher whose wildcard matches across dot separators. A wildcard in a certificate SAN or CN therefore matches subdomains of arbitrary depth, contrary to certificate wildcard rules. A network man-in-the-middle holding a broad wildcard certificate can impersonate hostnames it should not match. The fix restricts wildcard matching to a single DNS label.
You are affected if you are using a version that falls within the vulnerable range and you use the built-in TLS backend (MG_TLS_BUILTIN) as a client that validates server certificates.
cesanta.mongoose is vulnerable to Improper Certificate Validation in versions 7.14 - 7.21.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant