CVE-2022-37026
Summary
| CVE | CVE-2022-37026 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-21 14:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Erlang | Erlang/otp | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OTP 25.1 Released - Erlang News - Erlang Programming Language Forum - Erlang Forums | CONFIRM | erlangforums.com | |
| Comparing OTP-23.3.4.14...OTP-23.3.4.15 · erlang/otp · GitHub | MISC | github.com | |
| Erlang News & Announcements - Erlang Forums | MISC | erlangforums.com | |
| [SECURITY] [DLA 3491-1] erlang security update | MLIST | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182100 Debian Security Update for erlang (CVE-2022-37026)
- 199322 Ubuntu Security Notification for Erlang Vulnerability (USN-6059-1)
- 240974 Red Hat Update for OpenStack Platform 16.2.4 (RHSA-2022:8857)
- 377734 Erlang Client Authentication Bypass Vulnerability
- 502581 Alpine Linux Security Update for erlang
- 502850 Alpine Linux Security Update for erlang
- 505734 Alpine Linux Security Update for erlang
- 6000055 Debian Security Update for erlang (DLA 3491-1)
- 752876 SUSE Enterprise Linux Security Update for erlang (SUSE-SU-2022:4222-1)
- 752910 SUSE Enterprise Linux Security Update for erlang (SUSE-SU-2022:4215-1)
- 755111 SUSE Enterprise Linux Security Update for erlang (SUSE-SU-2023:4109-1)
- 904955 Common Base Linux Mariner (CBL-Mariner) Security Update for erlang (12322)
- 904978 Common Base Linux Mariner (CBL-Mariner) Security Update for erlang (12484)