An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://rustsec.org/advisories/RUSTSEC-2017-0003.html | third party advisory patch |