First published: Thu Mar 24 2022(Updated: )
OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OWASP Zed Attack Proxy | <=w2022-03-21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27820 is a vulnerability in OWASP Zed Attack Proxy (ZAP) where it does not verify the TLS certificate chain of an HTTPS server.
CVE-2022-27820 has a severity level of medium (4).
CVE-2022-27820 affects OWASP Zed Attack Proxy version up to and including w2022-03-21.
To fix CVE-2022-27820, update OWASP Zed Attack Proxy to a version after w2022-03-21 and ensure that it verifies the TLS certificate chain of HTTPS servers.
You can find more information about CVE-2022-27820 at the following references: [http://www.openwall.com/lists/oss-security/2022/03/24/3](http://www.openwall.com/lists/oss-security/2022/03/24/3), [https://github.com/zaproxy/zaproxy/issues/7165](https://github.com/zaproxy/zaproxy/issues/7165), [https://github.com/zaproxy/zaproxy/releases](https://github.com/zaproxy/zaproxy/releases).