The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonName and subjectAltName.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://scalyr-static.s3.amazonaws.com/technical-details/index.html | third party advisory exploit |