Improper X.509 Certificate Validation in lua-openssl 0.7.7-1

Improper X.509 Certificate Validation in lua-openssl 0.7.7-1

CVE-2020-9432 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

Learn more about our Web Application Penetration Testing UK.