Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2022-37026
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client…
Technology
Erlang/OTP
CVSS Score
9.8 / 10.0
Affected Versions
<23.3.4.15; >=24.0 <24.3.4.2; >=25.0 <25.0.2
Upstream Fix
See upstream advisory
Published
September 21, 2022
OSSeva Coverage
Fixed upstream
Description
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.
Is your Erlang/OTP deployment affected?
If you're running <23.3.4.15; >=24.0 <24.3.4.2; >=25.0 <25.0.2, you need this patch. Book a discovery call to get covered.