Back to Vulnerability Directory
HIGHFixed upstream

CVE-2020-35733

issue was discovered in Erlang/OTP before 23.2.2.

Technology

Erlang/OTP

CVSS Score

7.5 / 10.0

Affected Versions

<23.2.2

Upstream Fix

See upstream advisory

Published

January 15, 2021

OSSeva Coverage

Fixed upstream

Description

An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.

Is your Erlang/OTP deployment affected?

If you're running <23.2.2, you need this patch. Book a discovery call to get covered.