Back to Vulnerability Directory
HIGHFixed upstream
CVE-2020-35733
issue was discovered in Erlang/OTP before 23.2.2.
Technology
Erlang/OTP
CVSS Score
7.5 / 10.0
Affected Versions
<23.2.2
Upstream Fix
See upstream advisory
Published
January 15, 2021
OSSeva Coverage
Fixed upstream
Description
An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.
Is your Erlang/OTP deployment affected?
If you're running <23.2.2, you need this patch. Book a discovery call to get covered.