CWE一覧に戻る
CWE-295

不適切な証明書の検証

Improper Certificate Validation
脆弱性 レビュー中
JA

製品が証明書を検証しないか、誤って検証する。

EN

The product does not validate, or incorrectly validates, a certificate.

Scope: Integrity, Authentication / Impact: Bypass Protection Mechanism; Gain Privileges or Assume Identity
Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.
If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.
MITRE公式ページ — CWE-295