OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2022/03/23/1 | third party advisory mailing list |
https://github.com/zaproxy/zaproxy/releases | third party advisory release notes |
http://www.openwall.com/lists/oss-security/2022/03/24/3 | third party advisory mailing list |
https://github.com/zaproxy/zaproxy/issues/7165 | issue tracking third party advisory |