CVE-2024-45341
Last modified
CVE-2024-45341 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-45341?
How severe is CVE-2024-45341?
How do I fix CVE-2024-45341?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45336The HTTP client drops sensitive headers after following a cr…6.1
- CVE-2024-45337Applications and libraries which misuse connection.serverAut…9.1
- CVE-2024-45338An attacker can craft an input to the Parse functions that w…5.3
- CVE-2024-45339When logs are written to a widely-writable directory (the de…7.1
- CVE-2024-4534The KKProgressbar2 Free WordPress plugin through 1.1.4.2 do…6.1
- CVE-2024-45340Credentials provided via the new GOAUTH feature were not bei…8.8
- CVE-2024-45342Rejected reason: reserved but not needed
- CVE-2024-45343Rejected reason: reserved but not needed
- CVE-2024-45344Rejected reason: reserved but not needed
- CVE-2024-45345Rejected reason: reserved but not needed
- CVE-2024-45346The Xiaomi Security Center expresses heartfelt thanks to Ken…8.8
- CVE-2024-45347An unauthorized access vulnerability exists in the Xiaomi Mi…9.6
Are you affected by CVE-2024-45341?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
