lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://github.com/qorelanguage/qore/issues/3808 | third party advisory patch |
https://github.com/qorelanguage/qore/compare/release-0.9.4.1...release-0.9.4.2 | third party advisory patch |