CVE Feed

    Dashboard / CVE / CVE-2021-3450

    CVE-2021-3450

    The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values implemented in libcrypto perform this check. Therefore, where a purpose is set the certificate chain will still be rejected even when the strict flag has been used. A purpose is set by default in libssl client and server certificate verification routines, but it can be overridden or removed by an application. In order to be affected, an application must explicitly set the X509_V_FLAG_X509_STRICT verification flag and either not set a purpose for the certificate verification or, in the case of TLS client or server applications, override the default purpose. OpenSSL versions 1.1.1h and newer are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1h-1.1.1j).

    Published:Mar 25, 2021
    Last Modified:Nov 21, 2024
    EPS:Mar 25, 2021
    EPSS Score:0.00547
    CVSS Score:7.4

    Affected Products

    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Freebsd
    Product
    Freebsd
    Vendor
    Mcafee
    Product
    Web Gateway
    Vendor
    Mcafee
    Product
    Web Gateway Cloud Service
    Vendor
    Netapp
    Product
    Cloud Volumes Ontap Mediator
    Vendor
    Netapp
    Product
    Oncommand Workflow Automation
    Vendor
    Netapp
    Product
    Ontap Select Deploy Administration Utility
    Vendor
    Netapp
    Product
    Santricity Smi-s Provider
    Vendor
    Netapp
    Product
    Santricity Smi-s Provider Firmware
    Vendor
    Netapp
    Product
    Storagegrid
    Vendor
    Netapp
    Product
    Storagegrid Firmware
    Vendor
    Nodejs
    Product
    Node.js
    Vendor
    Openssl
    Product
    Openssl
    Vendor
    Oracle
    Product
    Commerce Guided Search
    Vendor
    Oracle
    Product
    Enterprise Manager For Storage Management
    Vendor
    Oracle
    Product
    Graalvm
    Vendor
    Oracle
    Product
    Jd Edwards Enterpriseone Tools
    Vendor
    Oracle
    Product
    Jd Edwards World Security
    Vendor
    Oracle
    Product
    Mysql Connectors
    Vendor
    Oracle
    Product
    Mysql Enterprise Monitor
    Vendor
    Oracle
    Product
    Mysql Server
    Vendor
    Oracle
    Product
    Mysql Workbench
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Peopletools
    Vendor
    Oracle
    Product
    Secure Backup
    Vendor
    Oracle
    Product
    Secure Global Desktop
    Vendor
    Oracle
    Product
    Weblogic Server
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Jboss Core Services
    Vendor
    Redhat
    Product
    Jboss Enterprise Web Server
    Vendor
    Redhat
    Product
    Rhev Hypervisor
    Vendor
    Sonicwall
    Product
    Capture Client
    Vendor
    Sonicwall
    Product
    Email Security
    Vendor
    Sonicwall
    Product
    Sma100
    Vendor
    Sonicwall
    Product
    Sma100 Firmware
    Vendor
    Sonicwall
    Product
    Sonicos
    Vendor
    Tenable
    Product
    Nessus
    Vendor
    Tenable
    Product
    Nessus Agent
    Vendor
    Tenable
    Product
    Nessus Network Monitor
    Vendor
    Windriver
    Product
    Linux

    Common Weakness Enumeration

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High