CVE-2019-18633: Critical severity europa eidas-node integration package vulnerability
Published Oct 30, 2019
·Updated
European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.
Affected Software
1 affected component
Europa Eidas-node Integration Package=2.1
Event History
Oct 30, 2019
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18633?
CVE-2019-18633 has a medium severity rating due to its potential to allow man-in-the-middle attacks.
2
How do I fix CVE-2019-18633?
To fix CVE-2019-18633, upgrade to the eIDAS-Node Integration Package version 2.3.1 or later.
3
What type of vulnerability is CVE-2019-18633?
CVE-2019-18633 is categorized as a missing certificate validation vulnerability.
4
Which versions of the eIDAS-Node Integration Package are affected by CVE-2019-18633?
Only version 2.1 of the eIDAS-Node Integration Package is confirmed to be affected by CVE-2019-18633.
5
What can happen if CVE-2019-18633 is exploited?
Exploitation of CVE-2019-18633 can lead to unauthorized access and data interception due to inadequate certificate validation.