#VU61607 Improper Certificate Validation in ZAP - CVE-2022-27820

 

#VU61607 Improper Certificate Validation in ZAP - CVE-2022-27820

Published: March 24, 2022


Vulnerability identifier: #VU61607
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-27820
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
ZAP
Software vendor:
OWASP

Description

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to missing TLS certificate chain validation. A remote attacker can perform MitM attack and intercept communication between the ZAP proxy and the server.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links