CWE一覧に戻る
CWE-298

証明書の有効期限の不適切な検証

Improper Validation of Certificate Expiration
脆弱性 レビュー中
JA

証明書の有効期限が検証されないか、または不正確に検証されるため、古いために放棄された証明書に信頼が割り当てられる可能性がある。

証明書の有効期限が考慮されない場合、証明書を通じて信頼が伝達されたとは限らない。したがって、証明書の有効性を検証することはできず、証明書の恩恵はすべて失われる。

EN

A certificate expiration is not validated or is incorrectly validated, so trust may be assigned to certificates that have been abandoned due to age.

When the expiration of a certificate is not taken into account, no trust has necessarily been conveyed through it. Therefore, the validity of the certificate cannot be verified and all benefit of the certificate is lost.

Scope: Integrity, Other / Impact: Other
Scope: Authentication, Other / Impact: Other
Check for expired certificates and provide the user with adequate information about the nature of the problem and how to proceed.
If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the expiration.
MITRE公式ページ — CWE-298