CVE-2022-27820 Information
Jun 07, 2022
cve
Description
OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Reference
https://www.openwall.com/lists/oss-security/2022/03/23/1 https://github.com/zaproxy/zaproxy/releases http://www.openwall.com/lists/oss-security/2022/03/24/3 https://github.com/zaproxy/zaproxy/issues/7165
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
4.0
Share on: