Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2022-37026

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client…

Technology

Erlang/OTP

CVSS Score

9.8 / 10.0

Affected Versions

<23.3.4.15; >=24.0 <24.3.4.2; >=25.0 <25.0.2

Upstream Fix

See upstream advisory

Published

September 21, 2022

OSSeva Coverage

Fixed upstream

Description

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

Is your Erlang/OTP deployment affected?

If you're running <23.3.4.15; >=24.0 <24.3.4.2; >=25.0 <25.0.2, you need this patch. Book a discovery call to get covered.