WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/201808-04 | vendor advisory |
https://trac.webkit.org/changeset/230886/webkit | issue tracking third party advisory patch |
https://bugs.webkit.org/show_bug.cgi?id=184804 | issue tracking third party advisory patch |