The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://www.consilium.europa.eu/en/policies/coronavirus/eu-digital-covid-certificate/ | product vendor advisory |
https://github.com/eu-digital-green-certificates/dgc-overview/security/advisories/GHSA-xcvc-p4fw-qmcj | third party advisory |