Improper Authentication in otp - CVE-2020-35733
Published: April 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper authentication in the ssl component when validating a certificate chain that includes a trusted root certificate. A remote attacker can present a fake certificate chain to disclose sensitive information.
The issue only occurs under conditions when the root certificate is sent in the chain.
Affected software
Arch Linux
Fedora
erlang
How to mitigate CVE-2020-35733
erlang - update to 23.2.2-1
erlang - update to 23.2.3-1.fc33