SB2022111680 - Improper Certificate Validation in Botan
Published: November 16, 2022 Updated: April 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Certificate Validation (CVE-ID: CVE-2022-43705)
The vulnerability allows a remote user to spoof certificate revocation status and bypass revocation checks.
The vulnerability exists due to improper certificate validation in OCSP response verification when processing embedded OCSP responder certificates. A remote privileged user can spoof a crafted OCSP response to spoof certificate revocation status and bypass revocation checks.
Only deployments that rely on OCSP for certificate revocation checks are affected. The issue can be exploited in scenarios such as OCSP stapling.
Remediation
Install update from vendor's website.